VYPR

zte-iccp-isupport-webui

by Zte

CVEs (5)

  • CVE-2026-49002CriMay 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

  • CVE-2026-49000HigMay 27, 2026
    risk 0.46cvss 7.0epss 0.00

    An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

  • CVE-2026-48999MedMay 27, 2026
    risk 0.37cvss 5.7epss 0.00

    Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user…

  • CVE-2026-49001MedMay 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampering with configuration data.

  • CVE-2026-44410LowMay 26, 2026
    risk 0.25cvss 3.8epss 0.00

    This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.