Vulnerability index

Browse CVEs

96 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mu5250 Firmware HIGH 7.5
CVE-2026-44409

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtai…

Mitigation only
Fix from $1,950 2026-05-22
Zx297520v3 Firmware MEDIUM 6.8
CVE-2026-40003

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validat…

Mitigation only
Fix from $1,600 2026-05-07
Nubia In Nx809j Firmware HIGH 8.8
CVE-2026-40002

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems f…

Mitigation only
Fix from $1,950 2026-04-17
Zxesm Iems HIGH 7.5
CVE-2026-40436

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control a…

Mitigation only
Fix from $1,950 2026-04-13
Zxhn H188a Firmware HIGH 7.1
CVE-2026-34472EPSS 9%

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t…

Mitigation only
Fix from $1,950 2026-03-30
Mf258k Pro Firmware HIGH 8.8
CVE-2025-66315

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att…

Mitigation only
Fix from $1,950 2026-01-09
Zxcloud Goldendb HIGH 7.5
CVE-2025-46575

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensit…

No fix yet
Fix from $1,950 2025-04-27
Zxcloud Goldendb MEDIUM 6.5
CVE-2025-46576

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privi…

Mitigation only
Fix from $1,600 2025-04-27
Nh8091 Firmware HIGH 8.8
CVE-2024-22067

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated…

Mitigation only
Fix from $1,950 2024-11-18
Mf258k Pro Firmware HIGH 8.8
CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent…

Mitigation only
Fix from $1,950 2024-10-29
Mf296r Firmware MEDIUM 6.5
CVE-2022-39068

There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could u…

Mitigation only
Fix from $1,600 2024-09-18
Zxv10 Et301 Firmware HIGH 8.8
CVE-2024-22069

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal w…

Mitigation only
Fix from $1,950 2024-08-08
Zxhn H388x Firmware MEDIUM 6.4
CVE-2023-25646

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permiss…

Mitigation only
Fix from $1,600 2024-06-20
Mf258 Firmware MEDIUM 6.1
CVE-2023-41781

There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack wil…

Mitigation only
Fix from $1,600 2024-01-10
Redmagic 8 Pro Firmware MEDIUM 5.5
CVE-2023-41784

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

No fix yet
Fix from $1,600 2024-01-04
Mc801a Firmware HIGH 8.8
CVE-2023-25643

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters,…

Mitigation only
Fix from $1,950 2023-12-14
Mc801a Firmware HIGH 7.5
CVE-2023-25644

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attack…

Mitigation only
Fix from $1,950 2023-12-14
Mc801a Firmware MEDIUM 6.5
CVE-2023-25642

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticate…

Mitigation only
Fix from $1,600 2023-12-14
Mf833u1 Firmware HIGH 8.0
CVE-2023-25651

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an auth…

Mitigation only
Fix from $1,950 2023-12-14
Mf286r Firmware HIGH 8.8
CVE-2023-25649

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter,…

Mitigation only
Fix from $1,950 2023-08-25
Up T2 4k Firmware HIGH 7.7
CVE-2023-25645

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application ca…

Mitigation only
Fix from $1,950 2023-06-16
Mf286r Firmware CRITICAL 9.8
CVE-2022-39073

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerabi…

Mitigation only
Fix from $2,300 2023-01-06
Mf286r Firmware MEDIUM 5.4
CVE-2022-39072

There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP inter…

Mitigation only
Fix from $1,600 2023-01-06
Zxhn H108ns Firmware HIGH 7.5
CVE-2022-45957EPSS 11%

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

No fix yet
Fix from $1,950 2022-12-12
Mf286r Firmware HIGH 8.8
CVE-2022-39066EPSS 27%

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authentic…

Mitigation only
Fix from $1,950 2022-11-22
Mf286r Firmware MEDIUM 6.5
CVE-2022-39067

There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacke…

Mitigation only
Fix from $1,600 2022-11-22
Zxmp M721 Firmware HIGH 7.5
CVE-2022-23141

ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled,…

Mitigation only
Fix from $1,950 2022-07-15
Mf297d Firmware HIGH 7.5
CVE-2022-23138

ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may …

Mitigation only
Fix from $1,950 2022-06-09
Zxmp M721 Firmware HIGH 8.8
CVE-2022-23139

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent w…

Mitigation only
Fix from $1,950 2022-05-12
Zxcdn Firmware MEDIUM 6.1
CVE-2022-23137

ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user…

Mitigation only
Fix from $1,600 2022-05-11