Vendor CVEs
Zte
All CVEs
220 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25649 | Med | 0.44 | 6.8 | 0.02 | Aug 25, 2023 | There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | ||
| CVE-2023-41784 | Med | 0.43 | 6.6 | 0.00 | Jan 4, 2024 | Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro | ||
| CVE-2018-7355 | Med | 0.43 | 6.1 | 0.02 | Sep 26, 2018 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS… | ||
| CVE-2015-7252 | Med | 0.43 | 6.1 | 0.03 | Dec 30, 2015 | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter. | ||
| CVE-2025-46578 | Med | 0.42 | 6.5 | 0.00 | Apr 27, 2025 | There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information. | ||
| CVE-2025-46577 | Med | 0.42 | 6.5 | 0.00 | Apr 27, 2025 | There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information. | ||
| CVE-2025-26704 | Med | 0.42 | 6.4 | 0.00 | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05. | ||
| CVE-2023-41780 | Med | 0.42 | 6.4 | 0.00 | Jan 3, 2024 | There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges. | ||
| CVE-2023-25644 | Med | 0.42 | 6.5 | 0.01 | Dec 14, 2023 | There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack. | ||
| CVE-2023-25650 | Med | 0.42 | 6.5 | 0.01 | Dec 14, 2023 | There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads. | ||
| CVE-2023-25648 | Med | 0.42 | 6.5 | 0.00 | Dec 14, 2023 | There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges. | ||
| CVE-2022-23143 | Med | 0.42 | 6.5 | 0.01 | Dec 5, 2022 | ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files. | ||
| CVE-2022-39067 | Med | 0.42 | 6.5 | 0.01 | Nov 22, 2022 | There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack. | ||
| CVE-2022-23135 | Med | 0.42 | 6.5 | 0.01 | Feb 24, 2022 | There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without… | ||
| CVE-2021-21735 | Med | 0.42 | 6.5 | 0.01 | Jun 10, 2021 | A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N… | ||
| CVE-2021-21734 | Med | 0.42 | 6.5 | 0.01 | May 28, 2021 | Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA10 F832 V1.1.1T7, ZXA10 F839 V1.1.0T8,… | ||
| CVE-2021-21729 | Med | 0.42 | 6.5 | 0.00 | Apr 13, 2021 | Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1 | ||
| CVE-2020-6868 | Med | 0.42 | 6.5 | 0.01 | Jun 1, 2020 | There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is created, but the HTTP proxy is available to be used to… | ||
| CVE-2020-6865 | Med | 0.42 | 6.5 | 0.01 | Apr 30, 2020 | ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to the request, the caller can directly view the internal error code location of the component. Attackers could exploit this… | ||
| CVE-2020-6864 | Med | 0.42 | 6.5 | 0.01 | Feb 27, 2020 | ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router. | ||
| CVE-2020-6863 | Med | 0.42 | 6.5 | 0.01 | Feb 27, 2020 | ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL. | ||
| CVE-2019-3428 | Med | 0.42 | 6.5 | 0.01 | Nov 22, 2019 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage. | ||
| CVE-2019-3420 | Med | 0.42 | 6.5 | 0.01 | Nov 13, 2019 | All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations. | ||
| CVE-2018-7361 | Med | 0.42 | 6.5 | 0.01 | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service. | ||
| CVE-2026-44408 | Med | 0.41 | 6.3 | 0.00 | May 19, 2026 | There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface. | ||
| CVE-2024-22062 | Med | 0.41 | 6.3 | 0.00 | Jul 9, 2024 | There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration. | ||
| CVE-2022-23137 | Med | 0.40 | 6.1 | 0.01 | May 11, 2022 | ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered. | ||
| CVE-2021-21747 | Med | 0.40 | 6.1 | 0.01 | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information. | ||
| CVE-2021-21746 | Med | 0.40 | 6.1 | 0.01 | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information. | ||
| CVE-2021-21738 | Med | 0.40 | 6.1 | 0.01 | Aug 5, 2021 | ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affect the operations of valid users. This affects:… | ||
| CVE-2020-6872 | Med | 0.40 | 6.1 | 0.01 | Jul 20, 2020 | The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects… | ||
| CVE-2019-3422 | Med | 0.40 | 6.2 | 0.01 | Nov 7, 2019 | The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can… | ||
| CVE-2024-22068 | Med | 0.39 | 6.0 | 0.00 | Oct 10, 2024 | Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier. | ||
| CVE-2023-25642 | Med | 0.38 | 5.9 | 0.01 | Dec 14, 2023 | There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. | ||
| CVE-2020-6862 | Med | 0.38 | 5.3 | 0.06 | Jan 17, 2020 | V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code. | ||
| CVE-2026-48999 | Med | 0.37 | 5.7 | 0.00 | May 27, 2026 | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user… | ||
| CVE-2026-44409 | Med | 0.37 | 5.7 | 0.00 | May 22, 2026 | There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure. | ||
| CVE-2026-44406 | Med | 0.37 | 5.7 | 0.00 | May 7, 2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;… | ||
| CVE-2025-26711 | Med | 0.37 | 5.7 | 0.00 | Sep 16, 2025 | There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface. | ||
| CVE-2025-26709 | Med | 0.37 | 5.7 | 0.00 | Aug 15, 2025 | There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface | ||
| CVE-2023-41781 | Med | 0.37 | 5.7 | 0.00 | Jan 10, 2024 | There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered. | ||
| CVE-2021-21725 | Med | 0.37 | 5.7 | 0.00 | Mar 5, 2021 | A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2. | ||
| CVE-2019-3419 | Med | 0.37 | 5.7 | 0.01 | Oct 31, 2019 | A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service. | ||
| CVE-2019-3415 | Med | 0.37 | 5.7 | 0.01 | Jul 11, 2019 | ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files. | ||
| CVE-2026-40004 | Med | 0.36 | 5.5 | 0.00 | May 7, 2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | ||
| CVE-2021-21742 | Med | 0.36 | 5.5 | 0.01 | Sep 25, 2021 | There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages. | ||
| CVE-2020-6867 | Med | 0.36 | 5.5 | 0.00 | Apr 30, 2020 | ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE… | ||
| CVE-2018-15006 | Med | 0.36 | 5.5 | 0.01 | Dec 28, 2018 | The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.android.zte.hiddenmenu (versionCode=23, versionName=6.0.1) that contains an exported… | ||
| CVE-2018-7356 | Med | 0.36 | 5.6 | 0.01 | Nov 1, 2018 | All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections. | ||
| CVE-2025-46576 | Med | 0.35 | 5.4 | 0.00 | Apr 27, 2025 | There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content. |
- risk 0.44cvss 6.8epss 0.02
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
- risk 0.43cvss 6.6epss 0.00
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
- risk 0.43cvss 6.1epss 0.02
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS…
- risk 0.43cvss 6.1epss 0.03
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.
- risk 0.42cvss 6.5epss 0.00
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
- risk 0.42cvss 6.5epss 0.00
There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.
- risk 0.42cvss 6.4epss 0.00
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.
- risk 0.42cvss 6.4epss 0.00
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.
- risk 0.42cvss 6.5epss 0.01
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
- risk 0.42cvss 6.5epss 0.01
There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.
- risk 0.42cvss 6.5epss 0.00
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
- risk 0.42cvss 6.5epss 0.01
ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.
- risk 0.42cvss 6.5epss 0.01
There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.
- risk 0.42cvss 6.5epss 0.01
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without…
- risk 0.42cvss 6.5epss 0.01
A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N…
- risk 0.42cvss 6.5epss 0.01
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA10 F832 V1.1.1T7, ZXA10 F839 V1.1.0T8,…
- risk 0.42cvss 6.5epss 0.00
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1
- risk 0.42cvss 6.5epss 0.01
There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is created, but the HTTP proxy is available to be used to…
- risk 0.42cvss 6.5epss 0.01
ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to the request, the caller can directly view the internal error code location of the component. Attackers could exploit this…
- risk 0.42cvss 6.5epss 0.01
ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.
- risk 0.42cvss 6.5epss 0.01
ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL.
- risk 0.42cvss 6.5epss 0.01
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.
- risk 0.42cvss 6.5epss 0.01
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.
- risk 0.42cvss 6.5epss 0.01
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service.
- risk 0.41cvss 6.3epss 0.00
There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.
- risk 0.41cvss 6.3epss 0.00
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
- risk 0.40cvss 6.1epss 0.01
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
- risk 0.40cvss 6.1epss 0.01
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
- risk 0.40cvss 6.1epss 0.01
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
- risk 0.40cvss 6.1epss 0.01
ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affect the operations of valid users. This affects:…
- risk 0.40cvss 6.1epss 0.01
The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects…
- risk 0.40cvss 6.2epss 0.01
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can…
- risk 0.39cvss 6.0epss 0.00
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
- risk 0.38cvss 5.9epss 0.01
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
- risk 0.38cvss 5.3epss 0.06
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
- risk 0.37cvss 5.7epss 0.00
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user…
- risk 0.37cvss 5.7epss 0.00
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.
- risk 0.37cvss 5.7epss 0.00
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;…
- risk 0.37cvss 5.7epss 0.00
There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface.
- risk 0.37cvss 5.7epss 0.00
There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface
- risk 0.37cvss 5.7epss 0.00
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
- risk 0.37cvss 5.7epss 0.00
A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2.
- risk 0.37cvss 5.7epss 0.01
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.
- risk 0.37cvss 5.7epss 0.01
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.
- risk 0.36cvss 5.5epss 0.00
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
- risk 0.36cvss 5.5epss 0.01
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
- risk 0.36cvss 5.5epss 0.00
ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE…
- risk 0.36cvss 5.5epss 0.01
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.android.zte.hiddenmenu (versionCode=23, versionName=6.0.1) that contains an exported…
- risk 0.36cvss 5.6epss 0.01
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.
- risk 0.35cvss 5.4epss 0.00
There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
Page 3 of 5