Vulnerabilities > ZTE > Zxr10 1800 2S Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-22066 Authentication Bypass by Capture-replay vulnerability in ZTE products
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router .
network
low complexity
zte CWE-294
6.5
2024-10-10 CVE-2024-22068 Weak Password Requirements vulnerability in ZTE products
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
network
low complexity
zte CWE-521
6.5
2018-07-25 CVE-2017-10935 Unspecified vulnerability in ZTE Zxr10 1800-2S Firmware 3.00.40
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
network
low complexity
zte
7.2
2017-09-19 CVE-2017-10931 Path Traversal vulnerability in ZTE Zxr10 1800-2S Firmware
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
network
low complexity
zte CWE-22
7.5
2017-09-19 CVE-2017-10930 Files or Directories Accessible to External Parties vulnerability in ZTE Zxr10 1800-2S Firmware
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
network
low complexity
zte CWE-552
critical
9.8