← Back

Zte

zte

183 CVEs • 326 products

Products (326)

Click to collapse
Toggle
Zxcloud Irai
zxcloud_irai
Zxv10 W300
zxv10_w300
Goldendb
goldendb
Zxdsl
zxdsl
Otcp Firmware
otcp_firmware
Zxin10 Cms
zxin10_cms
Score M
score_m
F460
f460
F660
f660
Zxdsl 831
zxdsl_831
Zxdsl 831cii
zxdsl_831cii
Hg110 Firmware
hg110_firmware
Mf28g Firmware
mf28g_firmware
Mf65 Firmware
mf65_firmware
Zxin10
zxin10
Usmartview
usmartview
F6x2w Firmware
f6x2w_firmware
Oscp
oscp
Zenic One R22b
zenic_one_r22b
F680 Firmware
f680_firmware
Ztemarket Apk
ztemarket_apk
Evdc
evdc

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zte
1Zxcloud Goldendata Vap
Jun 17, 2026
Dec 23, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have an information disclosure vulnerability. Attackers could use this vulnerability to collect data information and damage the system.
1Zte
1Zxcloud Goldendata Vap
Jun 17, 2026
Dec 23, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.
1Zte
1Zxcdn Iamweb Firmware
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.
1Zte
1Zxcdn Iamweb Firmware
Jun 17, 2026
Nov 22, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ inform...Show more
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.Show less
1Zte
1Zxhn H108n Firmware
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operat...Show more
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.Show less
1Zte
1Zxupn 9000e Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations.
1Zte
1Zxupn 9000e Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change pas...Show more
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.Show less
1Zte
1Mf910s Firmware
Jun 17, 2026
Nov 7, 2019
N/A· v4
6.2 MEDIUM· v3
1.9 LOW· v2
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is conf...Show more
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in the reverse way. If Telnet is opened, the attacker can remotely log in to the device through the cracked password, resulting in information leakage. The MF910S was end of service on October 23, 2019, ZTE recommends users to choose new products for the purpose of better security.Show less
1Zte
1Zxmp M721 Dx Firmware
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a den...Show more
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.Show less
1Zte
1Zxv10 B860a Firmware
Jun 17, 2026
Sep 23, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user termi...Show more
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.Show less
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute maliciou...Show more
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts.Show less
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Aug 15, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control...Show more
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system.Show less
1Zte
1Otcp Firmware
Jun 17, 2026
Jul 22, 2019
N/A· v4
4.8 MEDIUM· v3
2.3 LOW· v2
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user,...Show more
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process the returned result from the interface properly, the malicious script may be executed and the user cookie or other important information may be stolen.Show less
1Zte
1Zxmw Nr8000 Firmware
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.
1Zte
1Netnumen Dap Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.
1Zte
1Mf920 Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific...Show more
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.Show less
1Zte
1Mf920 Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to o...Show more
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components.Show less
1Zte
1Wf820+ Lte Outdoor Cpe Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requ...Show more
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this vulnerability to send unexpected requests to the server through the affected client.Show less
1Zte
1Wf820+ Lte Outdoor Cpe Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulne...Show more
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.Show less
1Zte
1Zxv10 B860av2.1 Chinamobile Firmware
Jun 17, 2026
Dec 28, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnera...Show more
ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.Show less