zte CVE Vulnerabilities & Metrics

Focus on zte vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About zte Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with zte. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total zte CVEs: 133
Earliest CVE date: 29 May 2012, 19:55 UTC
Latest CVE date: 18 Nov 2024, 07:15 UTC

Latest CVE reference: CVE-2024-22067

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 7

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -63.16%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -63.16%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical zte CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.09

Max CVSS: 10.0

Critical CVEs (≥9): 13

CVSS Range vs. Count

Range Count
0.0-3.9 59
4.0-6.9 59
7.0-8.9 14
9.0-10.0 13

CVSS Distribution Chart

Top 5 Highest CVSS zte CVEs

These are the five CVEs with the highest CVSS scores for zte, sorted by severity first and recency.

All CVEs for zte

CVE-2024-22067 zte vulnerability CVSS: 0 18 Nov 2024, 07:15 UTC

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

CVE-2024-22066 zte vulnerability CVSS: 0 29 Oct 2024, 09:15 UTC

There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.

CVE-2024-22065 zte vulnerability CVSS: 0 29 Oct 2024, 02:15 UTC

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVE-2024-22068 zte vulnerability CVSS: 0 10 Oct 2024, 09:15 UTC

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.

CVE-2022-39068 zte vulnerability CVSS: 0 18 Sep 2024, 02:15 UTC

There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.

CVE-2024-22062 zte vulnerability CVSS: 0 09 Jul 2024, 07:15 UTC

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

CVE-2023-25646 zte vulnerability CVSS: 0 20 Jun 2024, 07:15 UTC

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

CVE-2023-41781 zte vulnerability CVSS: 0 10 Jan 2024, 07:15 UTC

There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

CVE-2023-41782 zte vulnerability CVSS: 0 05 Jan 2024, 02:15 UTC

There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

CVE-2023-41784 zte vulnerability CVSS: 0 04 Jan 2024, 08:15 UTC

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

CVE-2023-41783 zte vulnerability CVSS: 0 03 Jan 2024, 02:15 UTC

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

CVE-2023-41780 zte vulnerability CVSS: 0 03 Jan 2024, 02:15 UTC

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

CVE-2023-41779 zte vulnerability CVSS: 0 03 Jan 2024, 02:15 UTC

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.

CVE-2023-41776 zte vulnerability CVSS: 0 03 Jan 2024, 02:15 UTC

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

CVE-2023-25644 zte vulnerability CVSS: 0 14 Dec 2023, 08:15 UTC

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

CVE-2023-25643 zte vulnerability CVSS: 0 14 Dec 2023, 08:15 UTC

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVE-2023-25642 zte vulnerability CVSS: 0 14 Dec 2023, 08:15 UTC

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

CVE-2023-25651 zte vulnerability CVSS: 0 14 Dec 2023, 07:15 UTC

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

CVE-2023-25650 zte vulnerability CVSS: 0 14 Dec 2023, 07:15 UTC

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

CVE-2023-25648 zte vulnerability CVSS: 0 14 Dec 2023, 07:15 UTC

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

CVE-2023-25649 zte vulnerability CVSS: 0 25 Aug 2023, 10:15 UTC

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVE-2023-25647 zte vulnerability CVSS: 0 17 Aug 2023, 03:15 UTC

There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

CVE-2023-25645 zte vulnerability CVSS: 0 16 Jun 2023, 19:15 UTC

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.

CVE-2022-39075 zte vulnerability CVSS: 0 30 May 2023, 23:15 UTC

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission.

CVE-2022-39074 zte vulnerability CVSS: 0 30 May 2023, 23:15 UTC

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission.

CVE-2022-39071 zte vulnerability CVSS: 0 30 May 2023, 23:15 UTC

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.

CVE-2022-39073 zte vulnerability CVSS: 0 06 Jan 2023, 19:15 UTC

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

CVE-2022-39072 zte vulnerability CVSS: 0 06 Jan 2023, 19:15 UTC

There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.

CVE-2022-45957 zte vulnerability CVSS: 0 12 Dec 2022, 15:15 UTC

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

CVE-2022-23143 zte vulnerability CVSS: 0 05 Dec 2022, 22:15 UTC

ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.

CVE-2022-39067 zte vulnerability CVSS: 0 22 Nov 2022, 17:15 UTC

There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.

CVE-2022-39066 zte vulnerability CVSS: 0 22 Nov 2022, 17:15 UTC

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

CVE-2022-23144 zte vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

CVE-2022-23142 zte vulnerability CVSS: 0 18 Jul 2022, 15:15 UTC

ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short time, which can make the product management websites not accessible.

CVE-2022-23141 zte vulnerability CVSS: 0 15 Jul 2022, 15:15 UTC

ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.

CVE-2022-23138 zte vulnerability CVSS: 5.0 09 Jun 2022, 15:15 UTC

ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.

CVE-2022-23139 zte vulnerability CVSS: 6.5 12 May 2022, 20:15 UTC

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

CVE-2022-23137 zte vulnerability CVSS: 4.3 11 May 2022, 16:15 UTC

ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

CVE-2022-23136 zte vulnerability CVSS: 3.5 30 Mar 2022, 16:15 UTC

There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device through the management page.

CVE-2022-23135 zte vulnerability CVSS: 5.5 24 Feb 2022, 19:15 UTC

There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.

CVE-2021-21749 zte vulnerability CVSS: 7.5 20 Oct 2021, 16:15 UTC

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

CVE-2021-21748 zte vulnerability CVSS: 7.5 20 Oct 2021, 16:15 UTC

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

CVE-2021-21745 zte vulnerability CVSS: 4.3 20 Oct 2021, 16:15 UTC

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

CVE-2021-21744 zte vulnerability CVSS: 5.0 20 Oct 2021, 16:15 UTC

ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of the device to be disabled.

CVE-2021-21743 zte vulnerability CVSS: 4.3 20 Oct 2021, 16:15 UTC

ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.

CVE-2021-21747 zte vulnerability CVSS: 4.3 20 Oct 2021, 15:15 UTC

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

CVE-2021-21746 zte vulnerability CVSS: 4.3 20 Oct 2021, 15:15 UTC

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

CVE-2021-21742 zte vulnerability CVSS: 4.3 25 Sep 2021, 00:15 UTC

There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.

CVE-2021-21741 zte vulnerability CVSS: 7.5 30 Aug 2021, 18:15 UTC

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

CVE-2021-21740 zte vulnerability CVSS: 2.1 09 Aug 2021, 16:15 UTC

There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.

CVE-2021-21739 zte vulnerability CVSS: 2.1 05 Aug 2021, 20:15 UTC

A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system authentication and detection, thus affecting signal transmission. This affects: <ZXCTN 6120H><V5.10.00B24>

CVE-2021-21738 zte vulnerability CVSS: 4.3 05 Aug 2021, 20:15 UTC

ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affect the operations of valid users. This affects: <ZXIPTV><ZXIPTV-EAS_PV5.06.04.09>

CVE-2021-21737 zte vulnerability CVSS: 5.0 24 Jun 2021, 11:15 UTC

A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10 B860H V5.0, V83011303.0010, V83011303.0016

CVE-2021-21736 zte vulnerability CVSS: 8.0 10 Jun 2021, 12:15 UTC

A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E

CVE-2021-21735 zte vulnerability CVSS: 4.0 10 Jun 2021, 12:15 UTC

A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0_EG1T4_TE.

CVE-2021-21734 zte vulnerability CVSS: 4.0 28 May 2021, 12:15 UTC

Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA10 F832 V1.1.1T7, ZXA10 F839 V1.1.0T8, ZXA10 F809 V3.2.1T1, ZXA10 F822P V1.1.1T7, ZXA10 F832 V2.00.00.01

CVE-2021-21731 zte vulnerability CVSS: 5.8 13 Apr 2021, 16:15 UTC

A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04

CVE-2021-21730 zte vulnerability CVSS: 5.0 13 Apr 2021, 16:15 UTC

A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attacks.This affects: ZXHN H168N V3.5.0_TY.T6

CVE-2021-21729 zte vulnerability CVSS: 4.3 13 Apr 2021, 16:15 UTC

Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1

CVE-2021-21727 zte vulnerability CVSS: 7.8 29 Mar 2021, 16:15 UTC

A ZTE product has a DoS vulnerability. A remote attacker can amplify traffic by sending carefully constructed IPv6 packets to the affected devices, which eventually leads to device denial of service. This affects:<ZXHN F623><All versions up to V6.0.0P3T33>

CVE-2021-21726 zte vulnerability CVSS: 2.1 12 Mar 2021, 19:15 UTC

Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set>

CVE-2021-21725 zte vulnerability CVSS: 2.7 05 Mar 2021, 17:15 UTC

A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2.

CVE-2021-21724 zte vulnerability CVSS: 2.1 26 Feb 2021, 03:15 UTC

A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly attenuated the optical signal to cause memory leak and abnormal service. This affects: ZXR10 8900E, all versions up to V3.03.20R2B30P1.

CVE-2021-21723 zte vulnerability CVSS: 4.3 26 Jan 2021, 18:16 UTC

Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operations, resulting in memory leak, which may eventually lead to device denial of service. This affects: ZXR10 9904, ZXR10 9908, ZXR10 9916, ZXR10 9904-S, ZXR10 9908-S; all versions up to V1.01.10.B12.

CVE-2021-21722 zte vulnerability CVSS: 2.1 14 Jan 2021, 16:15 UTC

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.

CVE-2020-6882 zte vulnerability CVSS: 5.0 21 Dec 2020, 18:15 UTC

ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>

CVE-2020-6881 zte vulnerability CVSS: 5.0 21 Dec 2020, 18:15 UTC

ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which will cause the device to deny service. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>

CVE-2020-6880 zte vulnerability CVSS: 7.5 01 Dec 2020, 16:15 UTC

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.

CVE-2020-6879 zte vulnerability CVSS: 2.7 19 Nov 2020, 17:15 UTC

Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request to the creation of a static routing rule configuration interface. The WEB service backend fails to effectively verify the abnormal input. As a result, the attacker can successfully use the vulnerability to tamper parameter values. This affects: ZXHN Z500 V1.0.0.2B1.1000 and ZXHN F670L V1.1.10P1N2E. This is fixed in ZXHN Z500 V1.0.1.1B1.1000 and ZXHN F670L V1.1.10P2N2.

CVE-2020-6877 zte vulnerability CVSS: 4.0 05 Nov 2020, 21:15 UTC

A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the handheld terminal and access the device illegally for operation. This affects: ZXA10 eODN V2.3P2T1

CVE-2020-6876 zte vulnerability CVSS: 3.5 26 Oct 2020, 16:15 UTC

A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker could trigger an XSS attack when the user browses the web page. Then the attacker could use the vulnerability to steal user cookies or destroy the page structure. This affects: eVDC ZXCLOUD-iROSV6.03.04

CVE-2020-6875 zte vulnerability CVSS: 5.0 05 Oct 2020, 15:15 UTC

A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-force attacks. This affects: <ZXONE 19700 SNPE><ZXONE8700V1.40R2B13_SNPE>

CVE-2020-6874 zte vulnerability CVSS: 5.5 01 Sep 2020, 21:15 UTC

A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV, ZXIPTV-WEB-PV5.09.08.04.

CVE-2020-6872 zte vulnerability CVSS: 4.3 20 Jul 2020, 18:15 UTC

The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.

CVE-2020-6871 zte vulnerability CVSS: 7.5 20 Jul 2020, 18:15 UTC

The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>

CVE-2020-6870 zte vulnerability CVSS: 5.2 24 Jun 2020, 16:15 UTC

The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, modify, upload, or delete files, causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115

CVE-2020-6869 zte vulnerability CVSS: 5.5 17 Jun 2020, 18:15 UTC

All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component exposure users can exploit this vulnerability to get the private cookie and execute silent installation.

CVE-2020-12695 zte vulnerability CVSS: 7.8 08 Jun 2020, 17:15 UTC

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVE-2020-6868 zte vulnerability CVSS: 3.3 01 Jun 2020, 13:15 UTC

There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is created, but the HTTP proxy is available to be used to bypass the limitation. An attacker can exploit the vulnerability to tamper with the parameter value. This affects: ZTE F680 V9.0.10P1N6

CVE-2020-6867 zte vulnerability CVSS: 2.1 30 Apr 2020, 22:15 UTC

ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE R22b versions V16.19.10P02SP002 and V16.19.10P02SP005.

CVE-2020-6866 zte vulnerability CVSS: 4.0 30 Apr 2020, 22:15 UTC

A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to cause a denial of service by issuing a specific command. This affects: ZXCTN 6500 version V2.10.00R3B87.

CVE-2020-6865 zte vulnerability CVSS: 4.0 30 Apr 2020, 22:15 UTC

ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to the request, the caller can directly view the internal error code location of the component. Attackers could exploit this vulnerability to obtain sensitive information. This affects: OSCP versions V16.19.10 and V16.19.20.

CVE-2020-6864 zte vulnerability CVSS: 3.3 27 Feb 2020, 17:15 UTC

ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.

CVE-2020-6863 zte vulnerability CVSS: 3.3 27 Feb 2020, 17:15 UTC

ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL.

CVE-2014-4019 zte vulnerability CVSS: 5.0 20 Feb 2020, 18:15 UTC

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.

CVE-2020-6862 zte vulnerability CVSS: 5.0 17 Jan 2020, 18:15 UTC

V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.

CVE-2019-3431 zte vulnerability CVSS: 5.0 23 Dec 2019, 19:15 UTC

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.

CVE-2019-3430 zte vulnerability CVSS: 4.0 23 Dec 2019, 19:15 UTC

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have an information disclosure vulnerability. Attackers could use this vulnerability to collect data information and damage the system.

CVE-2019-3429 zte vulnerability CVSS: 5.0 23 Dec 2019, 19:15 UTC

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.

CVE-2019-3428 zte vulnerability CVSS: 4.0 22 Nov 2019, 16:15 UTC

The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.

CVE-2019-3427 zte vulnerability CVSS: 6.5 22 Nov 2019, 16:15 UTC

The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.

CVE-2019-3420 zte vulnerability CVSS: 3.3 13 Nov 2019, 23:15 UTC

All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

CVE-2019-3426 zte vulnerability CVSS: 7.5 08 Nov 2019, 19:15 UTC

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations.

CVE-2019-3425 zte vulnerability CVSS: 7.5 08 Nov 2019, 19:15 UTC

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.

CVE-2019-3422 zte vulnerability CVSS: 1.9 07 Nov 2019, 20:15 UTC

The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in the reverse way. If Telnet is opened, the attacker can remotely log in to the device through the cracked password, resulting in information leakage. The MF910S was end of service on October 23, 2019, ZTE recommends users to choose new products for the purpose of better security.

CVE-2019-3419 zte vulnerability CVSS: 2.7 31 Oct 2019, 16:15 UTC

A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.

CVE-2019-3416 zte vulnerability CVSS: 10.0 23 Sep 2019, 14:15 UTC

All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

CVE-2019-3418 zte vulnerability CVSS: 3.5 15 Aug 2019, 15:15 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts.

CVE-2019-3417 zte vulnerability CVSS: 9.0 15 Aug 2019, 15:15 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system.

CVE-2019-3414 zte vulnerability CVSS: 2.3 22 Jul 2019, 19:15 UTC

All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process the returned result from the interface properly, the malicious script may be executed and the user cookie or other important information may be stolen.

CVE-2019-3415 zte vulnerability CVSS: 2.7 11 Jul 2019, 21:15 UTC

ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.

CVE-2019-3413 zte vulnerability CVSS: 3.5 11 Jun 2019, 20:29 UTC

All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.

CVE-2018-7366 zte vulnerability CVSS: 4.6 28 Dec 2018, 16:29 UTC

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

CVE-2018-7365 zte vulnerability CVSS: 6.5 20 Dec 2018, 14:29 UTC

All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unauthorized operations.

CVE-2018-7364 zte vulnerability CVSS: 10.0 07 Dec 2018, 14:29 UTC

All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with root privileges.

CVE-2018-7363 zte vulnerability CVSS: 3.3 16 Nov 2018, 15:29 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.

CVE-2018-7362 zte vulnerability CVSS: 9.0 16 Nov 2018, 15:29 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.

CVE-2018-7361 zte vulnerability CVSS: 3.3 16 Nov 2018, 15:29 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service.

CVE-2018-7360 zte vulnerability CVSS: 3.3 16 Nov 2018, 15:29 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attacker to get the GPON SN information via appviahttp service.

CVE-2018-7359 zte vulnerability CVSS: 7.5 16 Nov 2018, 15:29 UTC

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attacker to execute arbitrary code.

CVE-2018-7358 zte vulnerability CVSS: 5.8 14 Nov 2018, 15:29 UTC

ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.

CVE-2018-7357 zte vulnerability CVSS: 3.3 14 Nov 2018, 15:29 UTC

ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.

CVE-2018-7356 zte vulnerability CVSS: 5.0 01 Nov 2018, 13:29 UTC

All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.

CVE-2018-7355 zte vulnerability CVSS: 4.3 26 Sep 2018, 16:29 UTC

All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices.

CVE-2017-10937 zte vulnerability CVSS: 5.0 25 Jul 2018, 15:29 UTC

SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.

CVE-2017-10936 zte vulnerability CVSS: 5.0 25 Jul 2018, 15:29 UTC

SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.

CVE-2017-10935 zte vulnerability CVSS: 4.0 25 Jul 2018, 15:29 UTC

All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.

CVE-2017-16953 zte vulnerability CVSS: 5.0 01 Dec 2017, 17:29 UTC

connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.

CVE-2017-10933 zte vulnerability CVSS: 5.0 19 Oct 2017, 21:29 UTC

All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.

CVE-2017-10932 zte vulnerability CVSS: 10.0 28 Sep 2017, 01:29 UTC

All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.

CVE-2017-10931 zte vulnerability CVSS: 5.0 19 Sep 2017, 14:29 UTC

The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.

CVE-2017-10930 zte vulnerability CVSS: 5.0 19 Sep 2017, 14:29 UTC

The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.

CVE-2015-7255 zte vulnerability CVSS: 5.0 29 Aug 2017, 15:29 UTC

ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.

CVE-2015-7259 zte vulnerability CVSS: 9.0 24 Aug 2017, 20:29 UTC

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.

CVE-2015-7258 zte vulnerability CVSS: 9.0 24 Aug 2017, 20:29 UTC

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

CVE-2015-7257 zte vulnerability CVSS: 8.5 24 Aug 2017, 20:29 UTC

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

CVE-2017-3216 zte vulnerability CVSS: 10.0 20 Jun 2017, 00:29 UTC

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

CVE-2015-8703 zte vulnerability CVSS: 4.0 30 Dec 2015, 05:59 UTC

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.

CVE-2015-7252 zte vulnerability CVSS: 4.3 30 Dec 2015, 05:59 UTC

Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.

CVE-2015-7251 zte vulnerability CVSS: 10.0 30 Dec 2015, 05:59 UTC

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

CVE-2015-7250 zte vulnerability CVSS: 7.8 30 Dec 2015, 05:59 UTC

Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

CVE-2015-7249 zte vulnerability CVSS: 6.8 30 Dec 2015, 05:59 UTC

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.

CVE-2015-7248 zte vulnerability CVSS: 5.0 30 Dec 2015, 05:59 UTC

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/webproc HTML source code, a different vulnerability than CVE-2015-8703.

CVE-2014-9184 zte vulnerability CVSS: 5.0 02 Dec 2014, 18:59 UTC

ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.

CVE-2014-9183 zte vulnerability CVSS: 10.0 02 Dec 2014, 18:59 UTC

ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.

CVE-2014-9020 zte vulnerability CVSS: 4.3 20 Nov 2014, 17:50 UTC

Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter in a save action. NOTE: this issue was SPLIT from CVE-2014-9021 per ADT1 due to different affected products and codebases.

CVE-2014-9019 zte vulnerability CVSS: 6.8 20 Nov 2014, 17:50 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin user name or (2) conduct cross-site scripting (XSS) attacks via the sysUserName parameter in a save action to adminpasswd.cgi or (3) change the admin user password via the sysPassword parameter in a save action to adminpasswd.cgi.

CVE-2014-8493 zte vulnerability CVSS: 5.0 20 Nov 2014, 17:50 UTC

ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

CVE-2014-4154 zte vulnerability CVSS: 5.0 16 Jul 2014, 14:19 UTC

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.

CVE-2014-4018 zte vulnerability CVSS: 7.8 16 Jul 2014, 14:19 UTC

The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVE-2014-4155 zte vulnerability CVSS: 6.8 19 Jun 2014, 14:55 UTC

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

CVE-2014-2321 zte vulnerability CVSS: 10.0 11 Mar 2014, 13:01 UTC

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

CVE-2014-0329 zte vulnerability CVSS: 9.3 04 Feb 2014, 05:39 UTC

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.

CVE-2012-4746 zte vulnerability CVSS: 6.8 31 Aug 2012, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

CVE-2012-2949 zte vulnerability CVSS: 10.0 29 May 2012, 19:55 UTC

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.