VYPR

Vendor CVEs

Zte

All CVEs

220 total · sorted by risk
  • CVE-2015-7251CriDec 30, 2015
    risk 0.68cvss 9.8epss 0.11

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

  • CVE-2018-7364CriDec 7, 2018
    risk 0.65cvss 9.8epss 0.10

    All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with…

  • CVE-2025-46581CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.01

    ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

  • CVE-2024-10119CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.

  • CVE-2024-45415CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.00

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it…

  • CVE-2024-45414CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.00

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the…

  • CVE-2022-39073CriJan 6, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2022-39070CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

  • CVE-2021-21749CriOct 20, 2021
    risk 0.64cvss 9.8epss 0.02

    ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

  • CVE-2021-21748CriOct 20, 2021
    risk 0.64cvss 9.8epss 0.02

    ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

  • CVE-2021-21741CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.02

    There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

  • CVE-2021-21730CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attacks.This affects: ZXHN H168N V3.5.0_TY.T6

  • CVE-2020-6880CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.01

    A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all…

  • CVE-2020-6875CriOct 5, 2020
    risk 0.64cvss 9.8epss 0.01

    A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-force attacks. This affects: <ZXONE 19700…

  • CVE-2020-6871CriJul 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V0…

  • CVE-2019-3431CriDec 23, 2019
    risk 0.64cvss 9.8epss 0.00

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.

  • CVE-2019-3416CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.01

    All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

  • CVE-2019-3412CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.03

    All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.

  • CVE-2018-14991CriApr 25, 2019
    risk 0.64cvss 9.8epss 0.02

    The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a build fingerprint of ZTE/P895T20/urd:6.0.1/MMB29M/20170418.114928:user/release-keys, and the T-Mobile Revvl Plus with a build…

  • CVE-2017-10934CriJul 25, 2018
    risk 0.64cvss 9.8epss 0.03

    All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the…

  • CVE-2017-10932CriSep 28, 2017
    risk 0.64cvss 9.8epss 0.04

    All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library…

  • CVE-2017-10930CriSep 19, 2017
    risk 0.64cvss 9.8epss 0.01

    The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.

  • CVE-2017-3216CriJun 20, 2017
    risk 0.64cvss 9.8epss 0.05

    WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a…

  • CVE-2018-7360CriNov 16, 2018
    risk 0.62cvss 9.6epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attacker to get the GPON SN information via appviahttp service.

  • CVE-2015-7259HigAug 24, 2017
    risk 0.61cvss 8.8epss 0.09

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.

  • CVE-2015-7258HigAug 24, 2017
    risk 0.61cvss 8.8epss 0.13

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

  • CVE-2026-49002CriMay 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

  • CVE-2022-39066HigNov 22, 2022
    risk 0.59cvss 8.8epss 0.27

    There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

  • CVE-2022-23144CriSep 23, 2022
    risk 0.59cvss 9.1epss 0.01

    There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

  • CVE-2020-6874CriSep 1, 2020
    risk 0.59cvss 9.1epss 0.00

    A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV,…

  • CVE-2019-3409CriJun 11, 2019
    risk 0.59cvss 9.0epss 0.02

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.

  • CVE-2018-7359CriNov 16, 2018
    risk 0.59cvss 9.0epss 0.02

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attacker to execute arbitrary code.

  • CVE-2022-23139HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that…

  • CVE-2020-6877HigNov 5, 2020
    risk 0.57cvss 8.8epss 0.01

    A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the handheld terminal and access the device illegally for operation. This affects: ZXA10 eODN V2.3P2T1

  • CVE-2019-3426HigNov 8, 2019
    risk 0.57cvss 8.8epss 0.01

    The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations.

  • CVE-2019-3425HigNov 8, 2019
    risk 0.57cvss 8.8epss 0.01

    The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.

  • CVE-2019-3417HigAug 15, 2019
    risk 0.57cvss 8.8epss 0.02

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system.

  • CVE-2025-46579HigApr 27, 2025
    risk 0.55cvss 8.4epss 0.00

    There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

  • CVE-2023-25643HigDec 14, 2023
    risk 0.55cvss 8.4epss 0.02

    There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2026-34474HigMay 6, 2026
    risk 0.54cvss 7.5epss 0.25

    Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN…

  • CVE-2024-22064HigMay 14, 2024
    risk 0.54cvss 8.3epss 0.00

    ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are…

  • CVE-2024-45416HigSep 16, 2024
    risk 0.53cvss 8.1epss 0.01

    The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile…

  • CVE-2024-45413HigSep 16, 2024
    risk 0.53cvss 8.1epss 0.00

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated…

  • CVE-2021-21751HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.01

    ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause…

  • CVE-2021-21731HigApr 13, 2021
    risk 0.53cvss 8.1epss 0.00

    A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the…

  • CVE-2020-6869HigJun 17, 2020
    risk 0.53cvss 8.1epss 0.01

    All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component exposure users can exploit this vulnerability to get the private cookie and execute silent installation.

  • CVE-2014-4019HigFeb 20, 2020
    risk 0.53cvss 7.5epss 0.13

    ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.

  • CVE-2019-3424HigNov 18, 2019
    risk 0.53cvss 8.2epss 0.01

    authentication issues vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can automatically obtain access to web services from the authorized browser of the same computer and perform operations.

  • CVE-2017-16953HigDec 1, 2017
    risk 0.53cvss 7.5epss 0.11

    connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.

  • CVE-2015-7250HigDec 30, 2015
    risk 0.53cvss 7.5epss 0.16

    Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

Page 1 of 5