Show filters
248 Total Results
Displaying 51-60 of 248
Sort by:
Attacker Value
Unknown

CVE-2022-23141

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.
Attacker Value
Unknown

CVE-2022-23138

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.
Attacker Value
Unknown

CVE-2022-23139

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.
Attacker Value
Unknown

CVE-2022-23137

Disclosure Date: May 11, 2022 (last updated October 07, 2023)
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
Attacker Value
Unknown

CVE-2022-1164

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature
Attacker Value
Unknown

CVE-2022-23136

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device through the management page.
Attacker Value
Unknown

CVE-2022-23135

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.
Attacker Value
Unknown

CVE-2021-21751

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.
Attacker Value
Unknown

CVE-2021-21750

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.
Attacker Value
Unknown

CVE-2021-21745

Disclosure Date: October 20, 2021 (last updated November 28, 2024)
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.