Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 6.7% | — | Aztech Dsl5005enAI | 24/9/2025 | 17/6/2026 | Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication. | |
| Aplazada | Media (5.7) | 0.27% | — | ZTE T5400AI | 16/9/2025 | 17/6/2026 | There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface. | |
| Aplazada | Baja (3.5) | 0.24% | — | ZTE T5400AI | 16/9/2025 | 17/6/2026 | There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers can obtain information through interfaces without authorization, causing the risk of information disclosure. | |
| Aplazada | Media (5.7) | 0.27% | — | ZTE F50AI | 15/8/2025 | 17/6/2026 | There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface | |
| Aplazada | Alta (8.7) | 1.4% | — | ZTE Zxhn-f660tAIZTE Zxhn-f660aAI | 31/7/2025 | 17/6/2026 | ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices. | |
| Analizada | Alta (7.5) | 0.40% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL. | |
| Analizada | Alta (7.8) | 0.32% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed. | |
| Analizada | Alta (7.5) | 0.36% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information. | |
| Analizada | Alta (7.5) | 0.36% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information. | |
| Analizada | Media (6.5) | 0.29% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content. | |
| Analizada | Alta (7.5) | 0.38% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information. | |
| Analizada | Media (5.3) | 0.24% | — | ZTE Zxcloud Goldendb | 27/4/2025 | 17/6/2026 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information. | |
| Analizada | Media (5.3) | 0.24% | — | ZTE Goldendb | 11/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07. | |
| Analizada | Alta (7.5) | 0.31% | — | ZTE Goldendb | 11/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05. | |
| Analizada | Media (4.3) | 0.24% | — | ZTE Goldendb | 11/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05. | |
| Analizada | Media (4.3) | 0.25% | — | ZTE Goldendb | 11/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04. | |
| Analizada | Alta (7.5) | 0.39% | — | ZTE Goldendb | 11/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04. | |
| Aplazada | Media (5.3) | 0.29% | — | ZTE GoldendbAI | 11/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05. | |
| Aplazada | Media (4.2) | 0.13% | — | ZtelineAI | 7/3/2025 | 17/6/2026 | There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service. | |
| Aplazada | Media (5.9) | 0.29% | — | Aazztech WP CookieAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aazztech WP Cookie wp-cookie allows Stored XSS.This issue affects WP Cookie: from n/a through <= 1.0.0. | |
| Analizada | Crítica (9) | 0.83% | — | ZTE Zenic ONE R58 | 30/12/2024 | 17/6/2026 | The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices. | |
| Modificada | Alta (8.8) | 0.69% | — | ZTE Nh8091 Firmware | 18/11/2024 | 17/6/2026 | ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands. | |
| Analizada | Media (6.5) | 0.30% | — | ZTE Zxr10 1800-2s FirmwareZTE Zxr10 2800-4 FirmwareZTE Zxr10 3800-8 FirmwareZTE Zxr10 160 Firmware | 29/10/2024 | 17/6/2026 | There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device. | |
| Analizada | Alta (8.8) | 1.2% | — | ZTE Mf258k PRO Firmware | 29/10/2024 | 17/6/2026 | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | |
| Analizada | Crítica (9.8) | 0.95% | — | ZTE Wrtm326 Firmware | 18/10/2024 | 17/6/2026 | The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests. |