ZTE records
187 published records for vendor zte.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 16
- With a fix record
- 0.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-269 Improper Privilege Management12
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
187 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2018-7358Proof of concept | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerabzte · zxhn h168n firmware · CWE-287 | High8.8 | — | 89.6% | Nov 14, 2018 |
61This week | CVE-2018-7357Proof of concept | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerabzte · zxhn h168n firmware · CWE-306 | High8.8 | — | 87.9% | Nov 14, 2018 |
58Plan | CVE-2014-2321Proof of concept | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Critical10.0 | — | 59.3% | Mar 11, 2014 |
43Plan | CVE-2022-39066Proof of concept | There is a SQL injection vulnerability in ZTE MF286R.zte · mf286r firmware · CWE-89 | High8.8 | — | 26.5% | Nov 22, 2022 |
42Plan | CVE-2015-7251Proof of concept | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attazte · zxhn h108n r1a firmware · CWE-255 | Critical9.8 | — | 10.7% | Dec 30, 2015 |
42Plan | CVE-2018-7364No exploit | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.zte · zxin10 · CWE-284 | Critical9.8 | — | 10.3% | Dec 7, 2018 |
41Plan | CVE-2017-3216No exploit | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remotegreenpacket · ox350 firmware · CWE-306 | Critical9.8 | — | 5.2% | Jun 19, 2017 |
41Plan | CVE-2014-9183No exploit | ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.zte · zxdsl · CWE-255 | Critical10.0 | — | 3.6% | Dec 2, 2014 |
41Plan | CVE-2012-2949No exploit | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whiczte · score m · CWE-264 | Critical10.0 | — | 3.6% | May 29, 2012 |
40Plan | CVE-2014-0329Proof of concept | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remotzte · zxv10 w300 · CWE-255 | Critical9.3 | — | 8.5% | Feb 4, 2014 |
40Plan | CVE-2017-10932No exploit | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 zte · nr8120 firmware · CWE-502 | Critical9.8 | — | 4.1% | Sep 27, 2017 |
40Plan | CVE-2022-39073Proof of concept | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the zte · mf286r firmware · CWE-77 | Critical9.8 | — | 3.3% | Jan 6, 2023 |
40Plan | CVE-2017-10934No exploit | All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collezte · zxiptv-epg firmware · CWE-502 | Critical9.8 | — | 3.1% | Jul 25, 2018 |
40Plan | CVE-2019-3412No exploit | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.zte · mf920 firmware · CWE-78 | Critical9.8 | — | 2.9% | Jun 11, 2019 |
40Plan | CVE-2021-21741No exploit | There is a command execution vulnerability in a ZTE conference management system.zte · zxv10 m910 firmware · CWE-502 | Critical9.8 | — | 1.9% | Aug 30, 2021 |
40Plan | CVE-2020-6871No exploit | The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of thezte · r8500g4 firmware · CWE-287 | Critical9.8 | — | 1.9% | Jul 20, 2020 |
40Plan | CVE-2018-7359No exploit | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attackzte · zxhn f670 firmware · CWE-787 | Critical9.8 | — | 1.9% | Nov 16, 2018 |
40Plan | CVE-2021-21748No exploit | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Critical9.8 | — | 1.8% | Oct 20, 2021 |
39Monitor | CVE-2015-7258Proof of concept | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by dizte · zxv10 w300 firmware · CWE-255 | High8.8 | — | 12.9% | Aug 24, 2017 |
39Monitor | CVE-2021-21749No exploit | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Critical9.8 | — | 1.6% | Oct 20, 2021 |
39Monitor | CVE-2020-6880No exploit | A ZXELINK wireless controller has a SQL injection vulnerability.zte · zxv10 w908 firmware · CWE-89 | Critical9.8 | — | 1.2% | Dec 1, 2020 |
39Monitor | CVE-2020-6875No exploit | A ZTE product is impacted by the improper access control vulnerability.zte · zxone 19700 snpe firmware · CWE-306 | Critical9.8 | — | 1.2% | Oct 5, 2020 |
39Monitor | CVE-2017-10930No exploit | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being azte · zxr10 1800-2s firmware · CWE-552 | Critical9.8 | — | 1.1% | Sep 19, 2017 |
39Monitor | CVE-2019-3416No exploit | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.zte · zxv10 b860a firmware · CWE-20 | Critical9.8 | — | 1.1% | Sep 23, 2019 |
39Monitor | CVE-2021-21730No exploit | A ZTE product is impacted by improper access control vulnerability.zte · zxhn h168n firmware | Critical9.8 | — | 1.0% | Apr 13, 2021 |
- CVE-2018-735862This week
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerab
HighCVSS 8.8Proof of conceptEPSS 90%zte · zxhn h168n firmwareNov 14, 2018
- CVE-2018-735761This week
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerab
HighCVSS 8.8Proof of conceptEPSS 88%zte · zxhn h168n firmwareNov 14, 2018
- CVE-2014-232158Plan
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
CriticalCVSS 10.0Proof of conceptEPSS 59%zte · f460Mar 11, 2014
- CVE-2022-3906643Plan
There is a SQL injection vulnerability in ZTE MF286R.
HighCVSS 8.8Proof of conceptEPSS 27%zte · mf286r firmwareNov 22, 2022
- CVE-2015-725142Plan
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote atta
CriticalCVSS 9.8Proof of conceptEPSS 11%zte · zxhn h108n r1a firmwareDec 30, 2015
- CVE-2018-736442Plan
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.
CriticalCVSS 9.8No exploitEPSS 10%zte · zxin10Dec 7, 2018
- CVE-2017-321641Plan
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote
CriticalCVSS 9.8No exploitEPSS 5%greenpacket · ox350 firmwareJun 19, 2017
- CVE-2014-918341Plan
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.
CriticalCVSS 10.0No exploitEPSS 4%zte · zxdslDec 2, 2014
- CVE-2012-294941Plan
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whic
CriticalCVSS 10.0No exploitEPSS 4%zte · score mMay 29, 2012
- CVE-2014-032940Plan
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remot
CriticalCVSS 9.3Proof of conceptEPSS 9%zte · zxv10 w300Feb 4, 2014
- CVE-2017-1093240Plan
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950
CriticalCVSS 9.8No exploitEPSS 4%zte · nr8120 firmwareSep 27, 2017
- CVE-2022-3907340Plan
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the
CriticalCVSS 9.8Proof of conceptEPSS 3%zte · mf286r firmwareJan 6, 2023
- CVE-2017-1093440Plan
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Colle
CriticalCVSS 9.8No exploitEPSS 3%zte · zxiptv-epg firmwareJul 25, 2018
- CVE-2019-341240Plan
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.
CriticalCVSS 9.8No exploitEPSS 3%zte · mf920 firmwareJun 11, 2019
- CVE-2021-2174140Plan
There is a command execution vulnerability in a ZTE conference management system.
CriticalCVSS 9.8No exploitEPSS 2%zte · zxv10 m910 firmwareAug 30, 2021
- CVE-2020-687140Plan
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the
CriticalCVSS 9.8No exploitEPSS 2%zte · r8500g4 firmwareJul 20, 2020
- CVE-2018-735940Plan
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attack
CriticalCVSS 9.8No exploitEPSS 2%zte · zxhn f670 firmwareNov 16, 2018
- CVE-2021-2174840Plan
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
CriticalCVSS 9.8No exploitEPSS 2%zte · mf971r firmwareOct 20, 2021
- CVE-2015-725839Monitor
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by di
HighCVSS 8.8Proof of conceptEPSS 13%zte · zxv10 w300 firmwareAug 24, 2017
- CVE-2021-2174939Monitor
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
CriticalCVSS 9.8No exploitEPSS 2%zte · mf971r firmwareOct 20, 2021
- CVE-2020-688039Monitor
A ZXELINK wireless controller has a SQL injection vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%zte · zxv10 w908 firmwareDec 1, 2020
- CVE-2020-687539Monitor
A ZTE product is impacted by the improper access control vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%zte · zxone 19700 snpe firmwareOct 5, 2020
- CVE-2017-1093039Monitor
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a
CriticalCVSS 9.8No exploitEPSS 1%zte · zxr10 1800-2s firmwareSep 19, 2017
- CVE-2019-341639Monitor
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%zte · zxv10 b860a firmwareSep 23, 2019
- CVE-2021-2173039Monitor
A ZTE product is impacted by improper access control vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%zte · zxhn h168n firmwareApr 13, 2021