Skip to content
Noroxi

ZTE records

187 published records for vendor zte.

All records

187 records
  • CVE-2018-7358
    62This week

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerab

    HighCVSS 8.8Proof of conceptEPSS 90%

    zte · zxhn h168n firmwareNov 14, 2018

  • CVE-2018-7357
    61This week

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerab

    HighCVSS 8.8Proof of conceptEPSS 88%

    zte · zxhn h168n firmwareNov 14, 2018

  • web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst

    CriticalCVSS 10.0Proof of conceptEPSS 59%

    zte · f460Mar 11, 2014

  • There is a SQL injection vulnerability in ZTE MF286R.

    HighCVSS 8.8Proof of conceptEPSS 27%

    zte · mf286r firmwareNov 22, 2022

  • ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote atta

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    zte · zxhn h108n r1a firmwareDec 30, 2015

  • All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.

    CriticalCVSS 9.8No exploitEPSS 10%

    zte · zxin10Dec 7, 2018

  • WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote

    CriticalCVSS 9.8No exploitEPSS 5%

    greenpacket · ox350 firmwareJun 19, 2017

  • ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.

    CriticalCVSS 10.0No exploitEPSS 4%

    zte · zxdslDec 2, 2014

  • The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whic

    CriticalCVSS 10.0No exploitEPSS 4%

    zte · score mMay 29, 2012

  • The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remot

    CriticalCVSS 9.3Proof of conceptEPSS 9%

    zte · zxv10 w300Feb 4, 2014

  • All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950

    CriticalCVSS 9.8No exploitEPSS 4%

    zte · nr8120 firmwareSep 27, 2017

  • There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    zte · mf286r firmwareJan 6, 2023

  • All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Colle

    CriticalCVSS 9.8No exploitEPSS 3%

    zte · zxiptv-epg firmwareJul 25, 2018

  • All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.

    CriticalCVSS 9.8No exploitEPSS 3%

    zte · mf920 firmwareJun 11, 2019

  • There is a command execution vulnerability in a ZTE conference management system.

    CriticalCVSS 9.8No exploitEPSS 2%

    zte · zxv10 m910 firmwareAug 30, 2021

  • The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the

    CriticalCVSS 9.8No exploitEPSS 2%

    zte · r8500g4 firmwareJul 20, 2020

  • All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attack

    CriticalCVSS 9.8No exploitEPSS 2%

    zte · zxhn f670 firmwareNov 16, 2018

  • ZTE MF971R product has two stack-based buffer overflow vulnerabilities.

    CriticalCVSS 9.8No exploitEPSS 2%

    zte · mf971r firmwareOct 20, 2021

  • CVE-2015-7258
    39Monitor

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by di

    HighCVSS 8.8Proof of conceptEPSS 13%

    zte · zxv10 w300 firmwareAug 24, 2017

  • ZTE MF971R product has two stack-based buffer overflow vulnerabilities.

    CriticalCVSS 9.8No exploitEPSS 2%

    zte · mf971r firmwareOct 20, 2021

  • CVE-2020-6880
    39Monitor

    A ZXELINK wireless controller has a SQL injection vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    zte · zxv10 w908 firmwareDec 1, 2020

  • CVE-2020-6875
    39Monitor

    A ZTE product is impacted by the improper access control vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    zte · zxone 19700 snpe firmwareOct 5, 2020

  • The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a

    CriticalCVSS 9.8No exploitEPSS 1%

    zte · zxr10 1800-2s firmwareSep 19, 2017

  • CVE-2019-3416
    39Monitor

    All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    zte · zxv10 b860a firmwareSep 23, 2019

  • A ZTE product is impacted by improper access control vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    zte · zxhn h168n firmwareApr 13, 2021