Vulnerabilities > ZTE > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-08 CVE-2020-12695 Incorrect Default Permissions vulnerability in multiple products
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
7.5
2020-02-20 CVE-2014-4019 Information Exposure vulnerability in ZTE Zxv10 W300 Firmware W300V1.0.0Azrdlk
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.
network
low complexity
zte CWE-200
7.5
2019-11-22 CVE-2019-3427 Code Injection vulnerability in ZTE Zxcdn Iamweb Firmware 6.01.03.01
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability.
network
low complexity
zte CWE-94
7.2
2019-11-08 CVE-2019-3426 Improper Input Validation vulnerability in ZTE Zxupn-9000E Firmware
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability.
network
low complexity
zte CWE-20
8.8
2019-11-08 CVE-2019-3425 Incorrect Permission Assignment for Critical Resource vulnerability in ZTE Zxupn-9000E Firmware
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control.
network
low complexity
zte CWE-732
8.8
2019-08-15 CVE-2019-3417 OS Command Injection vulnerability in ZTE Zxhn F670 Firmware
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability.
network
low complexity
zte CWE-78
8.8
2019-06-11 CVE-2019-3411 Missing Authentication for Critical Function vulnerability in ZTE Mf920 Firmware
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability.
network
low complexity
zte CWE-306
7.5
2019-06-11 CVE-2019-3410 Cross-Site Request Forgery (CSRF) vulnerability in ZTE Wf820+ LTE Outdoor CPE Firmware
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users.
network
low complexity
zte CWE-352
8.8
2019-06-11 CVE-2019-3409 OS Command Injection vulnerability in ZTE Wf820+ LTE Outdoor CPE Firmware
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability.
network
low complexity
zte CWE-78
8.8
2018-12-20 CVE-2018-7365 Untrusted Search Path vulnerability in ZTE Usmartview and Zxcloud Irai
All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unauthorized operations.
network
low complexity
zte CWE-426
7.2