Show filters
248 Total Results
Displaying 31-40 of 248
Sort by:
Attacker Value
Unknown

CVE-2023-47755

Disclosure Date: November 22, 2023 (last updated December 02, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommerce Product Carousel Slider plugin <= 3.3.5 versions.
Attacker Value
Unknown

CVE-2023-25649

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Attacker Value
Unknown

CVE-2023-25647

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
Attacker Value
Unknown

CVE-2023-25645

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
Attacker Value
Unknown

CVE-2022-39075

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission.
Attacker Value
Unknown

CVE-2022-39074

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission.
Attacker Value
Unknown

CVE-2022-39071

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.
Attacker Value
Unknown

CVE-2022-45600

Disclosure Date: February 22, 2023 (last updated October 08, 2023)
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
Attacker Value
Unknown

CVE-2022-45599

Disclosure Date: February 22, 2023 (last updated October 08, 2023)
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.
Attacker Value
Unknown

CVE-2022-39073

Disclosure Date: January 06, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.