Vulnerabilities (CVE)

Filtered by vendor Zte Subscribe
Total 151 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6872 1 Zte 6 R5300g4, R5300g4 Firmware, R5500g4 and 3 more 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.
CVE-2020-6867 1 Zte 1 Zenic One R22b 2023-12-10 2.1 LOW 5.5 MEDIUM
ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE R22b versions V16.19.10P02SP002 and V16.19.10P02SP005.
CVE-2020-6866 1 Zte 2 Zxctn 6500, Zxctn 6500 Firmware 2023-12-10 4.0 MEDIUM 4.9 MEDIUM
A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to cause a denial of service by issuing a specific command. This affects: ZXCTN 6500 version V2.10.00R3B87.
CVE-2019-3425 1 Zte 2 Zxupn-9000e, Zxupn-9000e Firmware 2023-12-10 7.5 HIGH 8.8 HIGH
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.
CVE-2019-3430 1 Zte 1 Zxcloud Goldendata Vap 2023-12-10 4.0 MEDIUM 4.9 MEDIUM
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have an information disclosure vulnerability. Attackers could use this vulnerability to collect data information and damage the system.
CVE-2019-3428 1 Zte 2 Zxcdn Iamweb, Zxcdn Iamweb Firmware 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.
CVE-2019-3422 1 Zte 2 Mf910s, Mf910s Firmware 2023-12-10 1.9 LOW 6.2 MEDIUM
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in the reverse way. If Telnet is opened, the attacker can remotely log in to the device through the cracked password, resulting in information leakage. The MF910S was end of service on October 23, 2019, ZTE recommends users to choose new products for the purpose of better security.
CVE-2020-6862 1 Zte 2 F6x2w, F6x2w Firmware 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
CVE-2019-3427 1 Zte 2 Zxcdn Iamweb, Zxcdn Iamweb Firmware 2023-12-10 6.5 MEDIUM 7.2 HIGH
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.
CVE-2020-6863 1 Zte 2 E8820v3, E8820v3 Firmware 2023-12-10 3.3 LOW 6.5 MEDIUM
ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL.
CVE-2020-6864 1 Zte 2 E8820v3, E8820v3 Firmware 2023-12-10 3.3 LOW 6.5 MEDIUM
ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.
CVE-2019-3426 1 Zte 2 Zxupn-9000e, Zxupn-9000e Firmware 2023-12-10 7.5 HIGH 8.8 HIGH
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations.
CVE-2014-4019 1 Zte 2 Zxv10 W300, Zxv10 W300 Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.
CVE-2019-3431 1 Zte 1 Zxcloud Goldendata Vap 2023-12-10 5.0 MEDIUM 9.8 CRITICAL
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
CVE-2019-3429 1 Zte 1 Zxcloud Goldendata Vap 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.
CVE-2019-3419 1 Zte 2 Zxmp M721 Dx, Zxmp M721 Dx Firmware 2023-12-10 2.7 LOW 5.7 MEDIUM
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.
CVE-2019-3416 1 Zte 2 Zxv10 B860a, Zxv10 B860a Firmware 2023-12-10 10.0 HIGH 9.8 CRITICAL
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.
CVE-2019-3420 1 Zte 2 Zxhn H108n, Zxhn H108n Firmware 2023-12-10 3.3 LOW 6.5 MEDIUM
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.
CVE-2019-3413 1 Zte 2 Netnumen Dap, Netnumen Dap Firmware 2023-12-10 3.5 LOW 5.4 MEDIUM
All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.
CVE-2019-3417 1 Zte 2 Zxhn F670, Zxhn F670 Firmware 2023-12-10 9.0 HIGH 8.8 HIGH
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system.