VYPR
Vendor

Zte

Products
322
CVEs
220
Across products
170
Status
Private

Products

322
View all 322 products →

Recent CVEs

220
View all 220 CVEs →
  • CVE-2015-7251CriDec 30, 2015
    risk 0.68cvss 9.8epss 0.11

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

  • CVE-2018-7364CriDec 7, 2018
    risk 0.65cvss 9.8epss 0.10

    All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with…

  • CVE-2025-46581CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.01

    ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

  • CVE-2024-10119CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.

  • CVE-2024-45415CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.00

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it…

  • CVE-2024-45414CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.00

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the…

  • CVE-2022-39073CriJan 6, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2022-39070CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

  • CVE-2021-21749CriOct 20, 2021
    risk 0.64cvss 9.8epss 0.02

    ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

  • CVE-2021-21748CriOct 20, 2021
    risk 0.64cvss 9.8epss 0.02

    ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

  • CVE-2021-21741CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.02

    There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

  • CVE-2021-21730CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attacks.This affects: ZXHN H168N V3.5.0_TY.T6

  • CVE-2020-6880CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.01

    A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all…

  • CVE-2020-6875CriOct 5, 2020
    risk 0.64cvss 9.8epss 0.01

    A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-force attacks. This affects: <ZXONE 19700…

  • CVE-2020-6871CriJul 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V0…

  • CVE-2019-3431CriDec 23, 2019
    risk 0.64cvss 9.8epss 0.00

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.

  • CVE-2019-3416CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.01

    All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

  • CVE-2019-3412CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.03

    All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.

  • CVE-2018-14991CriApr 25, 2019
    risk 0.64cvss 9.8epss 0.02

    The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a build fingerprint of ZTE/P895T20/urd:6.0.1/MMB29M/20170418.114928:user/release-keys, and the T-Mobile Revvl Plus with a build…

  • CVE-2017-10934CriJul 25, 2018
    risk 0.64cvss 9.8epss 0.03

    All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the…