ZTE kayıtları
zte üreticisine ait 187 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 16
- Düzeltme kaydı olan
- %0,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-269 Improper Privilege Management12
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
187 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2018-7358Kavram kanıtı | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerabzte · zxhn h168n firmware · CWE-287 | Yüksek8,8 | — | %89,6 | 14 Kas 2018 |
61Bu hafta | CVE-2018-7357Kavram kanıtı | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerabzte · zxhn h168n firmware · CWE-306 | Yüksek8,8 | — | %87,9 | 14 Kas 2018 |
58Planlayın | CVE-2014-2321Kavram kanıtı | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Kritik10,0 | — | %59,3 | 11 Mar 2014 |
43Planlayın | CVE-2022-39066Kavram kanıtı | There is a SQL injection vulnerability in ZTE MF286R.zte · mf286r firmware · CWE-89 | Yüksek8,8 | — | %26,5 | 22 Kas 2022 |
42Planlayın | CVE-2015-7251Kavram kanıtı | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attazte · zxhn h108n r1a firmware · CWE-255 | Kritik9,8 | — | %10,7 | 30 Ara 2015 |
42Planlayın | CVE-2018-7364İstismar yok | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.zte · zxin10 · CWE-284 | Kritik9,8 | — | %10,3 | 7 Ara 2018 |
41Planlayın | CVE-2017-3216İstismar yok | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remotegreenpacket · ox350 firmware · CWE-306 | Kritik9,8 | — | %5,2 | 19 Haz 2017 |
41Planlayın | CVE-2014-9183İstismar yok | ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.zte · zxdsl · CWE-255 | Kritik10,0 | — | %3,6 | 2 Ara 2014 |
41Planlayın | CVE-2012-2949İstismar yok | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whiczte · score m · CWE-264 | Kritik10,0 | — | %3,6 | 29 May 2012 |
40Planlayın | CVE-2014-0329Kavram kanıtı | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remotzte · zxv10 w300 · CWE-255 | Kritik9,3 | — | %8,5 | 4 Şub 2014 |
40Planlayın | CVE-2017-10932İstismar yok | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 zte · nr8120 firmware · CWE-502 | Kritik9,8 | — | %4,1 | 27 Eyl 2017 |
40Planlayın | CVE-2022-39073Kavram kanıtı | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the zte · mf286r firmware · CWE-77 | Kritik9,8 | — | %3,3 | 6 Oca 2023 |
40Planlayın | CVE-2017-10934İstismar yok | All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collezte · zxiptv-epg firmware · CWE-502 | Kritik9,8 | — | %3,1 | 25 Tem 2018 |
40Planlayın | CVE-2019-3412İstismar yok | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.zte · mf920 firmware · CWE-78 | Kritik9,8 | — | %2,9 | 11 Haz 2019 |
40Planlayın | CVE-2021-21741İstismar yok | There is a command execution vulnerability in a ZTE conference management system.zte · zxv10 m910 firmware · CWE-502 | Kritik9,8 | — | %1,9 | 30 Ağu 2021 |
40Planlayın | CVE-2020-6871İstismar yok | The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of thezte · r8500g4 firmware · CWE-287 | Kritik9,8 | — | %1,9 | 20 Tem 2020 |
40Planlayın | CVE-2018-7359İstismar yok | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attackzte · zxhn f670 firmware · CWE-787 | Kritik9,8 | — | %1,9 | 16 Kas 2018 |
40Planlayın | CVE-2021-21748İstismar yok | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Kritik9,8 | — | %1,8 | 20 Eki 2021 |
39İzleyin | CVE-2015-7258Kavram kanıtı | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by dizte · zxv10 w300 firmware · CWE-255 | Yüksek8,8 | — | %12,9 | 24 Ağu 2017 |
39İzleyin | CVE-2021-21749İstismar yok | ZTE MF971R product has two stack-based buffer overflow vulnerabilities.zte · mf971r firmware · CWE-787 | Kritik9,8 | — | %1,6 | 20 Eki 2021 |
39İzleyin | CVE-2020-6880İstismar yok | A ZXELINK wireless controller has a SQL injection vulnerability.zte · zxv10 w908 firmware · CWE-89 | Kritik9,8 | — | %1,2 | 1 Ara 2020 |
39İzleyin | CVE-2020-6875İstismar yok | A ZTE product is impacted by the improper access control vulnerability.zte · zxone 19700 snpe firmware · CWE-306 | Kritik9,8 | — | %1,2 | 5 Eki 2020 |
39İzleyin | CVE-2017-10930İstismar yok | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being azte · zxr10 1800-2s firmware · CWE-552 | Kritik9,8 | — | %1,1 | 19 Eyl 2017 |
39İzleyin | CVE-2019-3416İstismar yok | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.zte · zxv10 b860a firmware · CWE-20 | Kritik9,8 | — | %1,1 | 23 Eyl 2019 |
39İzleyin | CVE-2021-21730İstismar yok | A ZTE product is impacted by improper access control vulnerability.zte · zxhn h168n firmware | Kritik9,8 | — | %1,0 | 13 Nis 2021 |
- CVE-2018-735862Bu hafta
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerab
YüksekCVSS 8,8Kavram kanıtıEPSS %90zte · zxhn h168n firmware14 Kas 2018
- CVE-2018-735761Bu hafta
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerab
YüksekCVSS 8,8Kavram kanıtıEPSS %88zte · zxhn h168n firmware14 Kas 2018
- CVE-2014-232158Planlayın
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
KritikCVSS 10,0Kavram kanıtıEPSS %59zte · f46011 Mar 2014
- CVE-2022-3906643Planlayın
There is a SQL injection vulnerability in ZTE MF286R.
YüksekCVSS 8,8Kavram kanıtıEPSS %27zte · mf286r firmware22 Kas 2022
- CVE-2015-725142Planlayın
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote atta
KritikCVSS 9,8Kavram kanıtıEPSS %11zte · zxhn h108n r1a firmware30 Ara 2015
- CVE-2018-736442Planlayın
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.
KritikCVSS 9,8İstismar yokEPSS %10zte · zxin107 Ara 2018
- CVE-2017-321641Planlayın
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote
KritikCVSS 9,8İstismar yokEPSS %5greenpacket · ox350 firmware19 Haz 2017
- CVE-2014-918341Planlayın
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.
KritikCVSS 10,0İstismar yokEPSS %4zte · zxdsl2 Ara 2014
- CVE-2012-294941Planlayın
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, whic
KritikCVSS 10,0İstismar yokEPSS %4zte · score m29 May 2012
- CVE-2014-032940Planlayın
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remot
KritikCVSS 9,3Kavram kanıtıEPSS %9zte · zxv10 w3004 Şub 2014
- CVE-2017-1093240Planlayın
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950
KritikCVSS 9,8İstismar yokEPSS %4zte · nr8120 firmware27 Eyl 2017
- CVE-2022-3907340Planlayın
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the
KritikCVSS 9,8Kavram kanıtıEPSS %3zte · mf286r firmware6 Oca 2023
- CVE-2017-1093440Planlayın
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Colle
KritikCVSS 9,8İstismar yokEPSS %3zte · zxiptv-epg firmware25 Tem 2018
- CVE-2019-341240Planlayın
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability.
KritikCVSS 9,8İstismar yokEPSS %3zte · mf920 firmware11 Haz 2019
- CVE-2021-2174140Planlayın
There is a command execution vulnerability in a ZTE conference management system.
KritikCVSS 9,8İstismar yokEPSS %2zte · zxv10 m910 firmware30 Ağu 2021
- CVE-2020-687140Planlayın
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the
KritikCVSS 9,8İstismar yokEPSS %2zte · r8500g4 firmware20 Tem 2020
- CVE-2018-735940Planlayın
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attack
KritikCVSS 9,8İstismar yokEPSS %2zte · zxhn f670 firmware16 Kas 2018
- CVE-2021-2174840Planlayın
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
KritikCVSS 9,8İstismar yokEPSS %2zte · mf971r firmware20 Eki 2021
- CVE-2015-725839İzleyin
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by di
YüksekCVSS 8,8Kavram kanıtıEPSS %13zte · zxv10 w300 firmware24 Ağu 2017
- CVE-2021-2174939İzleyin
ZTE MF971R product has two stack-based buffer overflow vulnerabilities.
KritikCVSS 9,8İstismar yokEPSS %2zte · mf971r firmware20 Eki 2021
- CVE-2020-688039İzleyin
A ZXELINK wireless controller has a SQL injection vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1zte · zxv10 w908 firmware1 Ara 2020
- CVE-2020-687539İzleyin
A ZTE product is impacted by the improper access control vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1zte · zxone 19700 snpe firmware5 Eki 2020
- CVE-2017-1093039İzleyin
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a
KritikCVSS 9,8İstismar yokEPSS %1zte · zxr10 1800-2s firmware19 Eyl 2017
- CVE-2019-341639İzleyin
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1zte · zxv10 b860a firmware23 Eyl 2019
- CVE-2021-2173039İzleyin
A ZTE product is impacted by improper access control vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1zte · zxhn h168n firmware13 Nis 2021