Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2015-7248EPSS 7%
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/w…
Zxhn H108n R1a Firmware
No fix yet
MEDIUM 5.0
CVE-2014-9184
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) …
Zxdsl
No fix yet
HIGH 10.0
CVE-2014-9183
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.
Zxdsl
Mitigation only
MEDIUM 6.8
CVE-2014-9019
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators …
Zxdsl
No fix yet
MEDIUM 5.0
CVE-2014-8493EPSS 8%
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.
Zxhn H108l Firmware
No fix yet
HIGH 7.8
CVE-2014-4018EPSS 6%
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote at…
Zxv10 W300 Firmware
No fix yet
MEDIUM 5.0
CVE-2014-4154EPSS 7%
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows…
Zxv10 W300 Firmware
No fix yet
MEDIUM 6.8
CVE-2014-4155
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the a…
Zxv10 W300 Firmware
No fix yet
HIGH 10.0
CVE-2014-2321EPSS 59%
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by …
F460
Mitigation only
HIGH 9.3
CVE-2014-0329EPSS 9%
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacke…
Zxv10 W300
No fix yet
MEDIUM 6.8
CVE-2012-4746
Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentic…
Zxdsl
No fix yet
HIGH 10.0
CVE-2012-2949
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows …
Score M
Mitigation only