zte

194 tracked vulnerabilities.

CVE-2023-25643 HIGH
ZTE MC801A and MC801A1 Firmware - Authenticated OS Command Injection
Dec 14, 2023
CVSS 8.4
EPSS 0.00
CVE-2023-25642 MEDIUM
ZTE MC801A and MC801A1 Firmware - Authenticated Denial of Service via TCP Port Parameter
Dec 14, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-25651 MEDIUM
ZTE MF833U1 and MF286R Firmware - Authenticated SQL Injection via SMS Interface Parameter
Dec 14, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-25650 MEDIUM
ZXCLOUD iRAI < 7.23.30 - Authenticated Arbitrary File Download via Request Parameter
Dec 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25648 MEDIUM
ZTE ZXCLOUD iRAI < 7.23.21 - Privilege Escalation via Weak Folder Permissions
Dec 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25649 MEDIUM
ZTE MF286R Firmware - Authenticated Command Injection via SET_DEVICE_LED Interface
Aug 25, 2023
CVSS 6.8
EPSS 0.00
CVE-2023-25647 MEDIUM
ZTE Axon 30/40 Pro/40 Ultra, Nubia Z50 Firmware < 3.0.0b06/1.0.0b16/2.0.0b17/1.0.0b19mr - Privilege Escalation
Aug 17, 2023
CVSS 4.7
EPSS 0.00
CVE-2023-25645 HIGH
ZTE AndroidTV STBs - Unauthenticated Data Deletion via Improper Permission Settings
Jun 16, 2023
CVSS 7.7
EPSS 0.00
CVE-2022-39068 MEDIUM
ZTE MF296R Firmware - Authenticated Denial of Service via SMS Parameter Buffer Overflow
Sep 18, 2024
CVSS 4.5
EPSS 0.00
CVE-2022-39075 HIGH
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 7.1
EPSS 0.00
CVE-2022-39074 LOW
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 3.3
EPSS 0.00
CVE-2022-39071 HIGH
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 7.1
EPSS 0.00
CVE-2022-39073 CRITICAL
ZTE MF286R Firmware - OS Command Injection
Jan 06, 2023
CVSS 9.8
EPSS 0.18
CVE-2022-39072 MEDIUM
ZTE Mobile Internet - SQL Injection
Jan 06, 2023
CVSS 5.4
EPSS 0.01
CVE-2022-45957 HIGH
ZTE ZXHN-H108NS Firmware H108NSV1.0.7u_ZRD_GR2_A68 - Remote Denial of Service via Stack Buffer Overflow
Dec 12, 2022
CVSS 7.5
EPSS 0.02
CVE-2022-23143 MEDIUM
ZTE OTCP Firmware < 2.21.40.06 - Unauthorized File Deletion and Modification
Dec 05, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-39070 CRITICAL
ZTE ZXA10 C350M and C300M Firmware 2.1.0-2.1.0xgp002.4 - Unauthenticated Remote Command Execution
Nov 22, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-39067 MEDIUM
ZTE MF286R < mf286r_b07 - Authenticated Denial of Service via WiFi Interface Parameter
Nov 22, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-39066 HIGH
ZTE MF286R < mf286r_b07 - Authenticated SQL Injection via Phonebook Interface
Nov 22, 2022
CVSS 8.8
EPSS 0.51
CVE-2022-39069 MEDIUM
ZTE ZAIP-AIE < 8.22.02 - SQL Injection
Nov 08, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-23144 CRITICAL
ZTE ZXvSTB Firmware < 2.01.02.01 - Broken Access Control
Sep 23, 2022
CVSS 9.1
EPSS 0.00
CVE-2022-23142 MEDIUM
ZTE ZXEN CG200 Firmware < 1.0.0p1n6_m - Denial of Service via HTTP GET Request Flood
Jul 18, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-23141 HIGH
ZTE ZXMP M721 Firmware - Sensitive Information Exposure via Serial Port Authentication Bypass
Jul 15, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-23138 HIGH
ZTE MF297D Firmware - Use of Insufficiently Random Values
Jun 09, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-23139 HIGH
ZTE ZXMP M721 Firmware - Incorrect Authorization via SFTP Folder Permission Mismatch
May 12, 2022
CVSS 8.8
EPSS 0.00