← Back to browse · API

CVE-2022-39066

Severity
HIGH
CVSS
8.8
EPSS
0.26542
Risk score
44.49
CISA KEV
No
PoC
No
Published
2022-11-22
Modified
2025-04-29
First seen
2026-08-07
Aliases
EUVD-2022-41612, GHSA-2M5W-88GG-379G
Products
n/a:MF286R Nordic_MF286R_B06
Sources
euvd EUVD-2022-41612

Description

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

References