Vulnerability index

Browse CVEs

162 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zxhn F680 Firmware MEDIUM 5.4
CVE-2022-23136

There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigge…

Mitigation only
Fix from $1,600 2022-03-30
Zxhn F677 Firmware MEDIUM 6.5
CVE-2022-23135

There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path,…

Fix: 9.0.0p1n29+
Fix from $1,600 2022-02-24
Zxin10 Cms HIGH 8.1
CVE-2021-21751

ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configu…

Fix: after 3.01.01.04
Fix from $1,950 2021-12-27
Zxin10 Cms HIGH 7.8
CVE-2021-21750

ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attac…

Fix: after 3.01.01.04
Fix from $1,950 2021-12-27
Mf971r Firmware CRITICAL 9.8
CVE-2021-21748

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

Mitigation only
Fix from $2,300 2021-10-20
Mf971r Firmware CRITICAL 9.8
CVE-2021-21749

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

Mitigation only
Fix from $2,300 2021-10-20
Mf971r Firmware HIGH 7.5
CVE-2021-21744

ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of…

Mitigation only
Fix from $1,950 2021-10-20
Mf971r Firmware MEDIUM 6.1
CVE-2021-21746

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

Mitigation only
Fix from $1,600 2021-10-20
Mf971r Firmware MEDIUM 6.1
CVE-2021-21747

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

Mitigation only
Fix from $1,600 2021-10-20
Axon 30 Pro Message Service MEDIUM 5.5
CVE-2021-21742

There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use …

Mitigation only
Fix from $1,600 2021-09-25
Zxv10 M910 Firmware CRITICAL 9.8
CVE-2021-21741

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit…

Mitigation only
Fix from $2,300 2021-08-30
Zxiptv Firmware MEDIUM 6.1
CVE-2021-21738

ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker…

Mitigation only
Fix from $1,600 2021-08-05
Zxv10 B860h V5.0 Firmware HIGH 7.5
CVE-2021-21737

A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attack…

Mitigation only
Fix from $1,950 2021-06-24
Zxhn Hs562 Firmware HIGH 7.2
CVE-2021-21736

A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cl…

Mitigation only
Fix from $1,950 2021-06-10
Zxhn H168n Firmware MEDIUM 6.5
CVE-2021-21735

A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit th…

Fix: after 3.5.0_eg1t4_te
Fix from $1,600 2021-06-10
Zxa10 F821 Firmware MEDIUM 6.5
CVE-2021-21734

Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects…

Mitigation only
Fix from $1,600 2021-05-28
Axon 11 5g Firmware HIGH 7.5
CVE-2021-21732

A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read so…

Fix: 2021.5.1+
Fix from $1,950 2021-05-19
Zxhn H168n Firmware CRITICAL 9.8
CVE-2021-21730

A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attack…

Mitigation only
Fix from $2,300 2021-04-13
Zxcloud Irai HIGH 8.1
CVE-2021-21731

A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whe…

Fix: 6.03.04+
Fix from $1,950 2021-04-13
Zxhn H168n Firmware MEDIUM 6.5
CVE-2021-21729

Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization oper…

Mitigation only
Fix from $1,600 2021-04-13
Zxa10 C300m Firmware MEDIUM 5.3
CVE-2021-21728

A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consume system processing resources…

Fix: 4.5+
Fix from $1,600 2021-04-09
Zxhn F623 Firmware HIGH 7.5
CVE-2021-21727

A ZTE product has a DoS vulnerability. A remote attacker can amplify traffic by sending carefully constructed IPv6 packets to the affected devices, w…

Fix: 6.0.0p3t34+
Fix from $1,950 2021-03-29
Zxhn H196q Firmware MEDIUM 5.7
CVE-2021-21725

A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directo…

Mitigation only
Fix from $1,600 2021-03-05
Zxr10 9904 Firmware HIGH 7.5
CVE-2021-21723

Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger …

Mitigation only
Fix from $1,950 2021-01-26
Zxhn E8810 Firmware HIGH 7.5
CVE-2020-6881

ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal …

Mitigation only
Fix from $1,950 2020-12-21
Zxhn E8810 Firmware HIGH 7.5
CVE-2020-6882

ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the dev…

Mitigation only
Fix from $1,950 2020-12-21
Zxv10 W908 Firmware CRITICAL 9.8
CVE-2020-6880

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, beca…

Mitigation only
Fix from $2,300 2020-12-01
Zxa10 Eodn Firmware HIGH 8.8
CVE-2020-6877

A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the…

Mitigation only
Fix from $1,950 2020-11-05
Evdc MEDIUM 5.4
CVE-2020-6876

A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. …

Mitigation only
Fix from $1,600 2020-10-26
Zxone 19700 Snpe Firmware CRITICAL 9.8
CVE-2020-6875

A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attacke…

Mitigation only
Fix from $2,300 2020-10-05