Vulnerabilities > ZTE

DATE CVE VULNERABILITY TITLE RISK
2014-02-04 CVE-2014-0329 Credentials Management vulnerability in ZTE Zxv10 W300 2.1.0
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.
network
zte CWE-255
critical
9.3
2012-08-31 CVE-2012-4746 Cross-Site Request Forgery (CSRF) vulnerability in ZTE Zxdsl 831Iiv7.5.0Az29Ov
Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.
network
zte CWE-352
6.8