Vulnerability index

Browse CVEs

162 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zxhn H108n R1a Firmware HIGH 7.5
CVE-2015-7248EPSS 7%

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/w…

No fix yet
Fix from $1,950 2015-12-30
Zxdsl MEDIUM 5.0
CVE-2014-9184

ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) …

No fix yet
Fix from $1,600 2014-12-02
Zxdsl HIGH 10.0
CVE-2014-9183

ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.

Mitigation only
Fix from $1,950 2014-12-02
Zxdsl MEDIUM 6.8
CVE-2014-9019

Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators …

No fix yet
Fix from $1,600 2014-11-20
Zxhn H108l Firmware MEDIUM 5.0
CVE-2014-8493EPSS 8%

ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

No fix yet
Fix from $1,600 2014-11-20
Zxv10 W300 Firmware HIGH 7.8
CVE-2014-4018EPSS 6%

The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote at…

No fix yet
Fix from $1,950 2014-07-16
Zxv10 W300 Firmware MEDIUM 5.0
CVE-2014-4154EPSS 7%

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows…

No fix yet
Fix from $1,600 2014-07-16
Zxv10 W300 Firmware MEDIUM 6.8
CVE-2014-4155

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2014-06-19
F460 HIGH 10.0
CVE-2014-2321EPSS 59%

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by …

Mitigation only
Fix from $1,950 2014-03-11
Zxv10 W300 HIGH 9.3
CVE-2014-0329EPSS 9%

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacke…

No fix yet
Fix from $1,950 2014-02-04
Zxdsl MEDIUM 6.8
CVE-2012-4746

Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentic…

No fix yet
Fix from $1,600 2012-08-31
Score M HIGH 10.0
CVE-2012-2949

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows …

Mitigation only
Fix from $1,950 2012-05-29