Записи ZTE
187 опубликованных записей вендора zte.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 16
- С записью об исправлении
- 0,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-269 Improper Privilege Management12
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
187 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2018-7358Proof of concept | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerabzte · zxhn h168n firmware · CWE-287 | Высокая8,8 | — | 89,6 % | 14 нояб. 2018 г. |
61На этой неделе | CVE-2018-7357Proof of concept | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerabzte · zxhn h168n firmware · CWE-306 | Высокая8,8 | — | 87,9 % | 14 нояб. 2018 г. |
58В плане | CVE-2014-2321Proof of concept | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Критическая10,0 | — | 59,3 % | 11 мар. 2014 г. |
43В плане | CVE-2022-39066Proof of concept | There is a SQL injection vulnerability in ZTE MF286R.zte · mf286r firmware · CWE-89 | Высокая8,8 | — | 26,5 % | 22 нояб. 2022 г. |
42В плане | CVE-2015-7251Proof of concept | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attazte · zxhn h108n r1a firmware · CWE-255 | Критическая9,8 | — | 10,7 % | 30 дек. 2015 г. |
42В плане | CVE-2018-7364Эксплойта нет | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.zte · zxin10 · CWE-284 | Критическая9,8 | — | 10,3 % | 7 дек. 2018 г. |
41В плане | CVE-2017-3216Эксплойта нет | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remotegreenpacket · ox350 firmware · CWE-306 | Критическая9,8 | — | 5,2 % | 19 июн. 2017 г. |
41В плане | CVE-2014-9183Эксплойта нет | ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.zte · zxdsl · CWE-255 | Критическая10,0 | — | 3,6 % | 2 дек. 2014 г. |
41В плане | CVE-2012-2949Эксплойта нет | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whiczte · score m · CWE-264 | Критическая10,0 | — | 3,6 % | 29 мая 2012 г. |
40В плане | CVE-2014-0329Proof of concept | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remotzte · zxv10 w300 · CWE-255 | Критическая9,3 | — | 8,5 % | 4 февр. 2014 г. |
40В плане | CVE-2017-10932Эксплойта нет | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 zte · nr8120 firmware · CWE-502 | Критическая9,8 | — | 4,1 % | 27 сент. 2017 г. |
40В плане | CVE-2022-39073Proof of concept | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the zte · mf286r firmware · CWE-77 | Критическая9,8 | — | 3,3 % | 6 янв. 2023 г. |
40В плане | CVE-2017-10934Эксплойта нет | All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collezte · zxiptv-epg firmware · CWE-502 | Критическая9,8 | — | 3,1 % | 25 июл. 2018 г. |
40В плане | CVE-2019-3412Эксплойта нет | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.zte · mf920 firmware · CWE-78 | Критическая9,8 | — | 2,9 % | 11 июн. 2019 г. |
40В плане | CVE-2021-21741Эксплойта нет | There is a command execution vulnerability in a ZTE conference management system.zte · zxv10 m910 firmware · CWE-502 | Критическая9,8 | — | 1,9 % | 30 авг. 2021 г. |
40В плане | CVE-2020-6871Эксплойта нет | The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of thezte · r8500g4 firmware · CWE-287 | Критическая9,8 | — | 1,9 % | 20 июл. 2020 г. |
40В плане | CVE-2018-7359Эксплойта нет | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attackzte · zxhn f670 firmware · CWE-787 | Критическая9,8 | — | 1,9 % | 16 нояб. 2018 г. |
40В плане | CVE-2021-21748Эксплойта нет | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Критическая9,8 | — | 1,8 % | 20 окт. 2021 г. |
39Наблюдать | CVE-2015-7258Proof of concept | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by dizte · zxv10 w300 firmware · CWE-255 | Высокая8,8 | — | 12,9 % | 24 авг. 2017 г. |
39Наблюдать | CVE-2021-21749Эксплойта нет | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Критическая9,8 | — | 1,6 % | 20 окт. 2021 г. |
39Наблюдать | CVE-2020-6880Эксплойта нет | A ZXELINK wireless controller has a SQL injection vulnerability.zte · zxv10 w908 firmware · CWE-89 | Критическая9,8 | — | 1,2 % | 1 дек. 2020 г. |
39Наблюдать | CVE-2020-6875Эксплойта нет | A ZTE product is impacted by the improper access control vulnerability.zte · zxone 19700 snpe firmware · CWE-306 | Критическая9,8 | — | 1,2 % | 5 окт. 2020 г. |
39Наблюдать | CVE-2017-10930Эксплойта нет | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being azte · zxr10 1800-2s firmware · CWE-552 | Критическая9,8 | — | 1,1 % | 19 сент. 2017 г. |
39Наблюдать | CVE-2019-3416Эксплойта нет | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.zte · zxv10 b860a firmware · CWE-20 | Критическая9,8 | — | 1,1 % | 23 сент. 2019 г. |
39Наблюдать | CVE-2021-21730Эксплойта нет | A ZTE product is impacted by improper access control vulnerability.zte · zxhn h168n firmware | Критическая9,8 | — | 1,0 % | 13 апр. 2021 г. |
- CVE-2018-735862На этой неделе
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerab
ВысокаяCVSS 8,8Proof of conceptEPSS 90 %zte · zxhn h168n firmware14 нояб. 2018 г.
- CVE-2018-735761На этой неделе
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerab
ВысокаяCVSS 8,8Proof of conceptEPSS 88 %zte · zxhn h168n firmware14 нояб. 2018 г.
- CVE-2014-232158В плане
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
КритическаяCVSS 10,0Proof of conceptEPSS 59 %zte · f46011 мар. 2014 г.
- CVE-2022-3906643В плане
There is a SQL injection vulnerability in ZTE MF286R.
ВысокаяCVSS 8,8Proof of conceptEPSS 27 %zte · mf286r firmware22 нояб. 2022 г.
- CVE-2015-725142В плане
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote atta
КритическаяCVSS 9,8Proof of conceptEPSS 11 %zte · zxhn h108n r1a firmware30 дек. 2015 г.
- CVE-2018-736442В плане
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %zte · zxin107 дек. 2018 г.
- CVE-2017-321641В плане
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %greenpacket · ox350 firmware19 июн. 2017 г.
- CVE-2014-918341В плане
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %zte · zxdsl2 дек. 2014 г.
- CVE-2012-294941В плане
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whic
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %zte · score m29 мая 2012 г.
- CVE-2014-032940В плане
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remot
КритическаяCVSS 9,3Proof of conceptEPSS 9 %zte · zxv10 w3004 февр. 2014 г.
- CVE-2017-1093240В плане
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %zte · nr8120 firmware27 сент. 2017 г.
- CVE-2022-3907340В плане
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the
КритическаяCVSS 9,8Proof of conceptEPSS 3 %zte · mf286r firmware6 янв. 2023 г.
- CVE-2017-1093440В плане
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Colle
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zte · zxiptv-epg firmware25 июл. 2018 г.
- CVE-2019-341240В плане
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zte · mf920 firmware11 июн. 2019 г.
- CVE-2021-2174140В плане
There is a command execution vulnerability in a ZTE conference management system.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zte · zxv10 m910 firmware30 авг. 2021 г.
- CVE-2020-687140В плане
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zte · r8500g4 firmware20 июл. 2020 г.
- CVE-2018-735940В плане
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attack
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zte · zxhn f670 firmware16 нояб. 2018 г.
- CVE-2021-2174840В плане
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zte · mf971r firmware20 окт. 2021 г.
- CVE-2015-725839Наблюдать
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by di
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %zte · zxv10 w300 firmware24 авг. 2017 г.
- CVE-2021-2174939Наблюдать
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zte · mf971r firmware20 окт. 2021 г.
- CVE-2020-688039Наблюдать
A ZXELINK wireless controller has a SQL injection vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxv10 w908 firmware1 дек. 2020 г.
- CVE-2020-687539Наблюдать
A ZTE product is impacted by the improper access control vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxone 19700 snpe firmware5 окт. 2020 г.
- CVE-2017-1093039Наблюдать
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxr10 1800-2s firmware19 сент. 2017 г.
- CVE-2019-341639Наблюдать
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxv10 b860a firmware23 сент. 2019 г.
- CVE-2021-2173039Наблюдать
A ZTE product is impacted by improper access control vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxhn h168n firmware13 апр. 2021 г.