Zte
zte
183 CVEs • 326 products
Products (326)
Click to collapseToggle
Products (326)
Click to collapse
CVEs (183)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zte 2Zxhn F670l Firmware Zxhn Z500 FirmwareJun 17, 2026 Nov 19, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST requ...Show more |
A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the handheld terminal and access the device illegally for operation. This...Show more |
A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker c...Show more |
1Zte 1Zxone 19700 Snpe Firmware Jun 17, 2026 Oct 5, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-forc...Show more |
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-forc...Show more |
1Zte 1Zxr10 2800 4 Almpufb(low) Firmware Jun 17, 2026 Sep 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets with valid http links, the remote attackers could use this vulnerability to cause the equipment WEB/...Show more |
1Zte 3R5300g4 Firmware R5500g4 FirmwareR8500g4 FirmwareJun 17, 2026 Jul 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script...Show more |
1Zte 3R5300g4 Firmware R5500g4 FirmwareR8500g4 FirmwareJun 17, 2026 Jul 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V0...Show more |
1Zte 1Netnumen U31 R10 Firmware Jun 17, 2026 Jun 24, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, mo...Show more |
All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component exposure users can exploit this vulnerability to get the private cookie and execute silent installati...Show more |
21Asus BroadcomCanon+18 more2175020 Z4a69a 5030 M2u92b5030 Z4a70a+214 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more |
There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is...Show more |
ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a lo...Show more |
A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to cause a denial of service by issuing a specific command. This affects: ZXCTN 6500 version V2.10.00R3...Show more |
ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to the request, the caller can directly view the internal error code locat...Show more |
ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect informa...Show more |
ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL. |
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0. |
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code. |
1Zte 1Zxcloud Goldendata Vap Jun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access. |