zte
194 tracked vulnerabilities.
CVE-2023-25643
HIGH
ZTE MC801A and MC801A1 Firmware - Authenticated OS Command Injection
Dec 14, 2023
CVSS 8.4
EPSS 0.00
CVE-2023-25642
MEDIUM
ZTE MC801A and MC801A1 Firmware - Authenticated Denial of Service via TCP Port Parameter
Dec 14, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-25651
MEDIUM
ZTE MF833U1 and MF286R Firmware - Authenticated SQL Injection via SMS Interface Parameter
Dec 14, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-25650
MEDIUM
ZXCLOUD iRAI < 7.23.30 - Authenticated Arbitrary File Download via Request Parameter
Dec 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25648
MEDIUM
ZTE ZXCLOUD iRAI < 7.23.21 - Privilege Escalation via Weak Folder Permissions
Dec 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25649
MEDIUM
ZTE MF286R Firmware - Authenticated Command Injection via SET_DEVICE_LED Interface
Aug 25, 2023
CVSS 6.8
EPSS 0.00
CVE-2023-25647
MEDIUM
ZTE Axon 30/40 Pro/40 Ultra, Nubia Z50 Firmware < 3.0.0b06/1.0.0b16/2.0.0b17/1.0.0b19mr - Privilege Escalation
Aug 17, 2023
CVSS 4.7
EPSS 0.00
CVE-2023-25645
HIGH
ZTE AndroidTV STBs - Unauthenticated Data Deletion via Improper Permission Settings
Jun 16, 2023
CVSS 7.7
EPSS 0.00
CVE-2022-39068
MEDIUM
ZTE MF296R Firmware - Authenticated Denial of Service via SMS Parameter Buffer Overflow
Sep 18, 2024
CVSS 4.5
EPSS 0.00
CVE-2022-39075
HIGH
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 7.1
EPSS 0.00
CVE-2022-39074
LOW
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 3.3
EPSS 0.00
CVE-2022-39071
HIGH
ZTE Mobile Phones - Info Disclosure
May 30, 2023
CVSS 7.1
EPSS 0.00
CVE-2022-39073
CRITICAL
ZTE MF286R Firmware - OS Command Injection
Jan 06, 2023
CVSS 9.8
EPSS 0.18
CVE-2022-39072
MEDIUM
ZTE Mobile Internet - SQL Injection
Jan 06, 2023
CVSS 5.4
EPSS 0.01
CVE-2022-45957
HIGH
ZTE ZXHN-H108NS Firmware H108NSV1.0.7u_ZRD_GR2_A68 - Remote Denial of Service via Stack Buffer Overflow
Dec 12, 2022
CVSS 7.5
EPSS 0.02
CVE-2022-23143
MEDIUM
ZTE OTCP Firmware < 2.21.40.06 - Unauthorized File Deletion and Modification
Dec 05, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-39070
CRITICAL
ZTE ZXA10 C350M and C300M Firmware 2.1.0-2.1.0xgp002.4 - Unauthenticated Remote Command Execution
Nov 22, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-39067
MEDIUM
ZTE MF286R < mf286r_b07 - Authenticated Denial of Service via WiFi Interface Parameter
Nov 22, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-39066
HIGH
ZTE MF286R < mf286r_b07 - Authenticated SQL Injection via Phonebook Interface
Nov 22, 2022
CVSS 8.8
EPSS 0.51
CVE-2022-39069
MEDIUM
ZTE ZAIP-AIE < 8.22.02 - SQL Injection
Nov 08, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-23144
CRITICAL
ZTE ZXvSTB Firmware < 2.01.02.01 - Broken Access Control
Sep 23, 2022
CVSS 9.1
EPSS 0.00
CVE-2022-23142
MEDIUM
ZTE ZXEN CG200 Firmware < 1.0.0p1n6_m - Denial of Service via HTTP GET Request Flood
Jul 18, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-23141
HIGH
ZTE ZXMP M721 Firmware - Sensitive Information Exposure via Serial Port Authentication Bypass
Jul 15, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-23138
HIGH
ZTE MF297D Firmware - Use of Insufficiently Random Values
Jun 09, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-23139
HIGH
ZTE ZXMP M721 Firmware - Incorrect Authorization via SFTP Folder Permission Mismatch
May 12, 2022
CVSS 8.8
EPSS 0.00
Products
zxcloud_irai 13
zxv10_w300_firmware 8
mf971r_firmware 7
zxcloud_goldendb 7
zxhn_f670_firmware 7
mf286r_firmware 6
zxhn_h108n_r1a_firmware 6
goldendb 5
zxhn_h168n_firmware 5
zxr10_1800-2s_firmware 5
zxv10_w300 5
axon_40_ultra_firmware 4
zxdsl 4
zxr10_160_firmware 4
zxr10_2800-4_firmware 4
zxr10_3800-8_firmware 4
ZXCLOUD iRAI 3
blade_a31_firmware 3
blade_a31_plus_firmware 3
blade_a3_lite_firmware 3
blade_a51_firmware 3
blade_a52_firmware 3
blade_a5_2019_firmware 3
blade_a5_2020_firmware 3
blade_a71_firmware 3
blade_a72_firmware 3
blade_a7s_firmware 3
blade_l210_firmware 3
blade_v20_smart_firmware 3
blade_v30_firmware 3
Quick Filters