← Back

Zte

zte

183 CVEs • 326 products

Products (326)

Click to collapse
Toggle
Zxcloud Irai
zxcloud_irai
Zxv10 W300
zxv10_w300
Goldendb
goldendb
Zxdsl
zxdsl
Otcp Firmware
otcp_firmware
Zxin10 Cms
zxin10_cms
Score M
score_m
F460
f460
F660
f660
Zxdsl 831
zxdsl_831
Zxdsl 831cii
zxdsl_831cii
Hg110 Firmware
hg110_firmware
Mf28g Firmware
mf28g_firmware
Mf65 Firmware
mf65_firmware
Zxin10
zxin10
Usmartview
usmartview
F6x2w Firmware
f6x2w_firmware
Oscp
oscp
Zenic One R22b
zenic_one_r22b
F680 Firmware
f680_firmware
Ztemarket Apk
ztemarket_apk
Evdc
evdc

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zte
1Goldendb
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.
1Zte
1Zenic One R58
Jun 17, 2026
Dec 30, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attac...Show more
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.Show less
1Zte
1Nh8091 Firmware
Jun 17, 2026
Nov 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
Jun 17, 2026
Oct 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
1Zte
1Mf258k Pro Firmware
Jun 17, 2026
Oct 29, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary comman...Show more
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.Show less
1Zte
1Wrtm326 Firmware
Jun 17, 2026
Oct 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
Jun 17, 2026
Oct 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8...Show more
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.Show less
1Zte
1Mf296r Firmware
Jun 17, 2026
Sep 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.
1Zte
2Zxv10 Et301 Firmware
Zxv10 Xt802 Firmware
Jun 17, 2026
Aug 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepti...Show more
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.Show less
1Zte
1Zxcloud Irai
Jun 17, 2026
Jul 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
1Zte
1Zxhn H388x Firmware
Jun 17, 2026
Jun 20, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the a...Show more
There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.Show less
1Zte
1Zxun Epdg
Jun 17, 2026
May 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devic...Show more
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked. Show less
1Zte
1Mf258 Firmware
Jun 17, 2026
Jan 10, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 5, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.
1Zte
1Redmagic 8 Pro Firmware
Jun 17, 2026
Jan 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
1Zte
2Mc801a1 Firmware
Mc801a Firmware
Jun 17, 2026
Dec 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack....Show more
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack. Show less