← Back

Zte

zte

183 CVEs • 326 products

Products (326)

Click to collapse
Toggle
Zxcloud Irai
zxcloud_irai
Zxv10 W300
zxv10_w300
Goldendb
goldendb
Zxdsl
zxdsl
Otcp Firmware
otcp_firmware
Zxin10 Cms
zxin10_cms
Score M
score_m
F460
f460
F660
f660
Zxdsl 831
zxdsl_831
Zxdsl 831cii
zxdsl_831cii
Hg110 Firmware
hg110_firmware
Mf28g Firmware
mf28g_firmware
Mf65 Firmware
mf65_firmware
Zxin10
zxin10
Usmartview
usmartview
F6x2w Firmware
f6x2w_firmware
Oscp
oscp
Zenic One R22b
zenic_one_r22b
F680 Firmware
f680_firmware
Ztemarket Apk
ztemarket_apk
Evdc
evdc

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zte
2Usmartview
Zxcloud Irai
Jun 17, 2026
Dec 20, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unauthorized operations.
1Zte
1Zxin10
Jun 17, 2026
Dec 7, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker ca...Show more
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with root privileges.Show less
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account creden...Show more
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.Show less
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service.
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attacker to get the GPON SN information via appviahttp service.
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attacker to execute arbitrary code.
1Zte
1Zxhn H168n Firmware
Jun 17, 2026
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.
1Zte
1Zxhn H168n Firmware
Jun 17, 2026
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.
1Zte
1Zxr10 8905e Firmware
Jun 17, 2026
Nov 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connecti...Show more
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.Show less
1Zte
2Mf65 Firmware
Mf65m1 Firmware
Jun 17, 2026
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker...Show more
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices.Show less
1Zte
1Zxiptv Ucm Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database...Show more
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.Show less
1Zte
1Zxcdn Sns Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database infor...Show more
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.Show less
1Zte
1Zxr10 1800 2s Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
1Zte
1Zxiptv Epg Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An...Show more
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.Show less
1Zte
1Zxdsl 831cii Firmware
May 13, 2026
Dec 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.
1Zte
1Zxdt22 Sf01 Firmware
May 13, 2026
Oct 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a...Show more
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.Show less
1Zte
6Nr8000tr Firmware
Nr8120 FirmwareNr8120a Firmware+3 more
May 13, 2026
Sep 28, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the...Show more
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.Show less
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
May 13, 2026
Sep 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator acco...Show more
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.Show less