Vulnerability index

Browse CVEs

162 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mu5250 Firmware HIGH 7.5
CVE-2026-44409

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtai…

Mitigation only
Fix from $1,950 2026-05-22
Zxcloud Irai HIGH 7.5
CVE-2026-44407

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of servi…

Fix: 7.25.43+
Fix from $1,950 2026-05-07
Zxcloud Irai HIGH 7.8
CVE-2026-44406

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijac…

Fix: 7.25.43+
Fix from $1,950 2026-05-07
Zxcloud Irai HIGH 7.8
CVE-2026-40004

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and …

Fix: 7.25.43+
Fix from $1,950 2026-05-07
Zx297520v3 Firmware MEDIUM 6.8
CVE-2026-40003

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validat…

Mitigation only
Fix from $1,600 2026-05-07
Nubia In Nx809j Firmware HIGH 8.8
CVE-2026-40002

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems f…

Mitigation only
Fix from $1,950 2026-04-17
Zxesm Iems HIGH 7.5
CVE-2026-40436

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control a…

Mitigation only
Fix from $1,950 2026-04-13
Zxhn H188a Firmware HIGH 7.1
CVE-2026-34472EPSS 9%

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t…

Mitigation only
Fix from $1,950 2026-03-30
Mf258k Pro Firmware HIGH 8.8
CVE-2025-66315

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att…

Mitigation only
Fix from $1,950 2026-01-09
Zxcloud Goldendb HIGH 7.5
CVE-2025-46580

There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of busines…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.8
CVE-2025-46579

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users d…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46578

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject com…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46575

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensit…

No fix yet
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46577

There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Zxcloud Goldendb MEDIUM 6.5
CVE-2025-46576

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privi…

Mitigation only
Fix from $1,600 2025-04-27
Zxcloud Goldendb MEDIUM 5.3
CVE-2025-46574

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensit…

Fix: 6.1.03.11+
Fix from $1,600 2025-04-27
Goldendb HIGH 7.5
CVE-2025-26705

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Fix: 6.1.03.06+
Fix from $1,950 2025-03-11
Goldendb MEDIUM 5.3
CVE-2025-26706

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

Fix: after 6.1.03.07
Fix from $1,600 2025-03-11
Goldendb HIGH 7.5
CVE-2025-26702

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Fix: 6.1.03.05+
Fix from $1,950 2025-03-11
Zenic One R58 CRITICAL 9.0
CVE-2024-22063

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tam…

Fix: 16.24.40+
Fix from $2,300 2024-12-30
Nh8091 Firmware HIGH 8.8
CVE-2024-22067

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated…

Mitigation only
Fix from $1,950 2024-11-18
Zxr10 1800 2s Firmware MEDIUM 6.5
CVE-2024-22066

There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerab…

Fix: after 3.00.40
Fix from $1,600 2024-10-29
Mf258k Pro Firmware HIGH 8.8
CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent…

Mitigation only
Fix from $1,950 2024-10-29
Wrtm326 Firmware CRITICAL 9.8
CVE-2024-10119

The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary sy…

Fix: after 2.3.20
Fix from $2,300 2024-10-18
Zxr10 1800 2s Firmware MEDIUM 6.5
CVE-2024-22068

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality By…

Fix: 6.00.10+
Fix from $1,600 2024-10-10
Mf296r Firmware MEDIUM 6.5
CVE-2022-39068

There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could u…

Mitigation only
Fix from $1,600 2024-09-18
Zxv10 Et301 Firmware HIGH 8.8
CVE-2024-22069

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal w…

Mitigation only
Fix from $1,950 2024-08-08
Zxcloud Irai HIGH 8.8
CVE-2024-22062

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permis…

Fix: 7.23.40+
Fix from $1,950 2024-07-09
Zxhn H388x Firmware MEDIUM 6.4
CVE-2023-25646

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permiss…

Mitigation only
Fix from $1,600 2024-06-20
Zxun Epdg MEDIUM 6.5
CVE-2024-22064

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic …

Fix: 5.20.20+
Fix from $1,600 2024-05-14