VYPR

Vendor CVEs

Zte

All CVEs

220 total · sorted by risk
  • CVE-2025-26706MedMar 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

  • CVE-2022-39072MedJan 6, 2023
    risk 0.35cvss 5.4epss 0.00

    There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.

  • CVE-2022-23136MedMar 30, 2022
    risk 0.35cvss 5.4epss 0.00

    There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device through the management page.

  • CVE-2021-21728MedApr 9, 2021
    risk 0.35cvss 5.3epss 0.01

    A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consume system processing resources by flushing a large number of packets to the port, and successfully exploiting this vulnerability could reduce system processing…

  • CVE-2020-6876MedOct 26, 2020
    risk 0.35cvss 5.4epss 0.01

    A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker could trigger an XSS attack when the user browses the web…

  • CVE-2020-6873MedSep 1, 2020
    risk 0.35cvss 5.3epss 0.01

    A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets with valid http links, the remote attackers could use this vulnerability to cause the equipment WEB/TELNET module denial of service and make the equipment be…

  • CVE-2019-3429MedDec 23, 2019
    risk 0.35cvss 5.3epss 0.01

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.

  • CVE-2019-3423MedNov 18, 2019
    risk 0.35cvss 5.3epss 0.01

    permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.

  • CVE-2019-3418MedAug 15, 2019
    risk 0.35cvss 5.4epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts.

  • CVE-2019-3413MedJun 11, 2019
    risk 0.35cvss 5.4epss 0.01

    All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.

  • CVE-2015-7249MedDec 30, 2015
    risk 0.35cvss 4.9epss 0.06

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.

  • CVE-2026-49001MedMay 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampering with configuration data.

  • CVE-2026-40001MedMay 6, 2026
    risk 0.34cvss 5.2epss 0.00

    There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traversal bypass.

  • CVE-2025-46583MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.

  • CVE-2025-26705MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

  • CVE-2025-26707MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

  • CVE-2022-39069MedNov 8, 2022
    risk 0.34cvss 5.3epss 0.00

    There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.

  • CVE-2022-23142MedJul 18, 2022
    risk 0.34cvss 5.3epss 0.01

    ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short time, which can make the product management websites not accessible.

  • CVE-2026-40003MedMay 7, 2026
    risk 0.33cvss 5.1epss 0.00

    ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the…

  • CVE-2026-40002MedApr 17, 2026
    risk 0.33cvss 5.0epss 0.00

    Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write…

  • CVE-2018-7365MedDec 20, 2018
    risk 0.33cvss 5.1epss 0.01

    All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unauthorized operations.

  • CVE-2025-46575MedApr 27, 2025
    risk 0.32cvss 4.9epss 0.00

    There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

  • CVE-2025-26702MedMar 11, 2025
    risk 0.32cvss 4.9epss 0.00

    Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

  • CVE-2021-21745MedOct 20, 2021
    risk 0.32cvss 4.3epss 0.56

    ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

  • CVE-2021-21733MedMay 19, 2021
    risk 0.32cvss 4.9epss 0.01

    The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis according to the information returned by the program, and then obtain some sensitive information. This affects ZXCDN V7.01 all versions up to IAMV7.01.01.02.

  • CVE-2020-6866MedApr 30, 2020
    risk 0.32cvss 4.9epss 0.01

    A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to cause a denial of service by issuing a specific command. This affects: ZXCTN 6500 version V2.10.00R3B87.

  • CVE-2019-3430MedDec 23, 2019
    risk 0.32cvss 4.9epss 0.01

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have an information disclosure vulnerability. Attackers could use this vulnerability to collect data information and damage the system.

  • CVE-2026-44407MedMay 7, 2026
    risk 0.31cvss 4.7epss 0.00

    A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

  • CVE-2023-25647MedAug 17, 2023
    risk 0.31cvss 4.7epss 0.00

    There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

  • CVE-2019-3414MedJul 22, 2019
    risk 0.31cvss 4.8epss 0.00

    All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the…

  • CVE-2018-14995MedDec 28, 2018
    risk 0.31cvss 4.7epss 0.00

    The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971/peony:7.1.1/NMF26V/20171129.143111:user/release-keys, the ZTE ZMAX Pro Android…

  • CVE-2021-21739MedAug 5, 2021
    risk 0.30cvss 4.6epss 0.00

    A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system…

  • CVE-2019-3410MedJun 11, 2019
    risk 0.30cvss 4.6epss 0.00

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this…

  • CVE-2022-39068MedSep 18, 2024
    risk 0.29cvss 4.5epss 0.00

    There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.

  • CVE-2023-41779MedJan 3, 2024
    risk 0.29cvss 4.4epss 0.00

    There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.

  • CVE-2021-21724MedFeb 26, 2021
    risk 0.29cvss 4.4epss 0.00

    A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly attenuated the optical signal to cause memory leak and abnormal service. This affects: ZXR10 8900E,…

  • CVE-2021-21722MedJan 14, 2021
    risk 0.29cvss 4.4epss 0.00

    A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A…

  • CVE-2025-66315MedJan 9, 2026
    risk 0.28cvss 4.3epss 0.00

    There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

  • CVE-2025-26703MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

  • CVE-2023-41783MedJan 3, 2024
    risk 0.28cvss 4.3epss 0.01

    There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

  • CVE-2023-25651MedDec 14, 2023
    risk 0.28cvss 4.3epss 0.00

    There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

  • CVE-2021-21743MedOct 20, 2021
    risk 0.28cvss 4.3epss 0.01

    ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.

  • CVE-2018-7366MedDec 28, 2018
    risk 0.28cvss 4.3epss 0.01

    ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform…

  • CVE-2018-7363MedNov 16, 2018
    risk 0.28cvss 4.3epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.

  • CVE-2025-46574MedApr 27, 2025
    risk 0.27cvss 4.1epss 0.00

    There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

  • CVE-2025-26708MedMar 7, 2025
    risk 0.27cvss 4.2epss 0.00

    There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.

  • CVE-2026-44410LowMay 26, 2026
    risk 0.25cvss 3.8epss 0.00

    This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

  • CVE-2023-41782LowJan 5, 2024
    risk 0.25cvss 3.9epss 0.00

    There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

  • CVE-2025-26710LowSep 16, 2025
    risk 0.23cvss 3.5epss 0.00

    There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers can obtain information through interfaces without authorization, causing the risk of information disclosure.

  • CVE-2020-6879LowNov 19, 2020
    risk 0.23cvss 3.5epss 0.01

    Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request to the creation of a…

Page 4 of 5