Show filters
248 Total Results
Displaying 161-170 of 248
Sort by:
Attacker Value
Unknown
CVE-2017-10930
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
0
Attacker Value
Unknown
CVE-2015-7255
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.
0
Attacker Value
Unknown
CVE-2015-7258
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.
0
Attacker Value
Unknown
CVE-2015-7259
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.
0
Attacker Value
Unknown
CVE-2015-7257
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
0
Attacker Value
Unknown
CVE-2017-3216
Disclosure Date: June 20, 2017 (last updated November 26, 2024)
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
0
Attacker Value
Unknown
CVE-2015-7249
Disclosure Date: December 30, 2015 (last updated November 25, 2024)
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
0
Attacker Value
Unknown
CVE-2015-7252
Disclosure Date: December 30, 2015 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.
0
Attacker Value
Unknown
CVE-2015-7251
Disclosure Date: December 30, 2015 (last updated November 25, 2024)
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
0
Attacker Value
Unknown
CVE-2015-7250
Disclosure Date: December 30, 2015 (last updated November 25, 2024)
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
0