VYPR

Vendor CVEs

Zte

All CVEs

220 total · sorted by risk
  • CVE-2023-25649MedAug 25, 2023
    risk 0.44cvss 6.8epss 0.02

    There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2023-41784MedJan 4, 2024
    risk 0.43cvss 6.6epss 0.00

    Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

  • CVE-2018-7355MedSep 26, 2018
    risk 0.43cvss 6.1epss 0.02

    All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS…

  • CVE-2015-7252MedDec 30, 2015
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.

  • CVE-2025-46578MedApr 27, 2025
    risk 0.42cvss 6.5epss 0.00

    There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.

  • CVE-2025-46577MedApr 27, 2025
    risk 0.42cvss 6.5epss 0.00

    There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

  • CVE-2025-26704MedMar 11, 2025
    risk 0.42cvss 6.4epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

  • CVE-2023-41780MedJan 3, 2024
    risk 0.42cvss 6.4epss 0.00

    There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

  • CVE-2023-25644MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

  • CVE-2023-25650MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

  • CVE-2023-25648MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.00

    There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

  • CVE-2022-23143MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.

  • CVE-2022-39067MedNov 22, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.

  • CVE-2022-23135MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without…

  • CVE-2021-21735MedJun 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N…

  • CVE-2021-21734MedMay 28, 2021
    risk 0.42cvss 6.5epss 0.01

    Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA10 F832 V1.1.1T7, ZXA10 F839 V1.1.0T8,…

  • CVE-2021-21729MedApr 13, 2021
    risk 0.42cvss 6.5epss 0.00

    Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1

  • CVE-2020-6868MedJun 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is created, but the HTTP proxy is available to be used to…

  • CVE-2020-6865MedApr 30, 2020
    risk 0.42cvss 6.5epss 0.01

    ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to the request, the caller can directly view the internal error code location of the component. Attackers could exploit this…

  • CVE-2020-6864MedFeb 27, 2020
    risk 0.42cvss 6.5epss 0.01

    ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.

  • CVE-2020-6863MedFeb 27, 2020
    risk 0.42cvss 6.5epss 0.01

    ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL.

  • CVE-2019-3428MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.

  • CVE-2019-3420MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.01

    All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

  • CVE-2018-7361MedNov 16, 2018
    risk 0.42cvss 6.5epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service.

  • CVE-2026-44408MedMay 19, 2026
    risk 0.41cvss 6.3epss 0.00

    There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface.

  • CVE-2024-22062MedJul 9, 2024
    risk 0.41cvss 6.3epss 0.00

    There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

  • CVE-2022-23137MedMay 11, 2022
    risk 0.40cvss 6.1epss 0.01

    ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

  • CVE-2021-21747MedOct 20, 2021
    risk 0.40cvss 6.1epss 0.01

    ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

  • CVE-2021-21746MedOct 20, 2021
    risk 0.40cvss 6.1epss 0.01

    ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

  • CVE-2021-21738MedAug 5, 2021
    risk 0.40cvss 6.1epss 0.01

    ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affect the operations of valid users. This affects:…

  • CVE-2020-6872MedJul 20, 2020
    risk 0.40cvss 6.1epss 0.01

    The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects…

  • CVE-2019-3422MedNov 7, 2019
    risk 0.40cvss 6.2epss 0.01

    The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can…

  • CVE-2024-22068MedOct 10, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.

  • CVE-2023-25642MedDec 14, 2023
    risk 0.38cvss 5.9epss 0.01

    There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

  • CVE-2020-6862MedJan 17, 2020
    risk 0.38cvss 5.3epss 0.06

    V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.

  • CVE-2026-48999MedMay 27, 2026
    risk 0.37cvss 5.7epss 0.00

    Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user…

  • CVE-2026-44409MedMay 22, 2026
    risk 0.37cvss 5.7epss 0.00

    There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

  • CVE-2026-44406MedMay 7, 2026
    risk 0.37cvss 5.7epss 0.00

    ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;…

  • CVE-2025-26711MedSep 16, 2025
    risk 0.37cvss 5.7epss 0.00

    There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface.

  • CVE-2025-26709MedAug 15, 2025
    risk 0.37cvss 5.7epss 0.00

    There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface

  • CVE-2023-41781MedJan 10, 2024
    risk 0.37cvss 5.7epss 0.00

    There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

  • CVE-2021-21725MedMar 5, 2021
    risk 0.37cvss 5.7epss 0.00

    A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2.

  • CVE-2019-3419MedOct 31, 2019
    risk 0.37cvss 5.7epss 0.01

    A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.

  • CVE-2019-3415MedJul 11, 2019
    risk 0.37cvss 5.7epss 0.01

    ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.

  • CVE-2026-40004MedMay 7, 2026
    risk 0.36cvss 5.5epss 0.00

    There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.

  • CVE-2021-21742MedSep 25, 2021
    risk 0.36cvss 5.5epss 0.01

    There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.

  • CVE-2020-6867MedApr 30, 2020
    risk 0.36cvss 5.5epss 0.00

    ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE…

  • CVE-2018-15006MedDec 28, 2018
    risk 0.36cvss 5.5epss 0.01

    The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.android.zte.hiddenmenu (versionCode=23, versionName=6.0.1) that contains an exported…

  • CVE-2018-7356MedNov 1, 2018
    risk 0.36cvss 5.6epss 0.01

    All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.

  • CVE-2025-46576MedApr 27, 2025
    risk 0.35cvss 5.4epss 0.00

    There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.