Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.53% | 💥 PoC | ZTE E8820v3 Firmware | 27/2/2020 | 17/6/2026 | ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router. | |
| Modificada | Media (6.5) | 0.58% | — | ZTE E8820v3 Firmware | 27/2/2020 | 17/6/2026 | ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 20/2/2020 | 17/6/2026 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0. | |
| Modificada | Media (5.3) | 6.3% | 💥 Exploit | ZTE F6x2w Firmware | 17/1/2020 | 17/6/2026 | V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code. | |
| Modificada | Crítica (9.8) | 0.40% | — | ZTE Zxcloud Goldendata VAP | 23/12/2019 | 17/6/2026 | All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access. | |
| Modificada | Media (4.9) | 0.87% | — | ZTE Zxcloud Goldendata VAP | 23/12/2019 | 17/6/2026 | All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have an information disclosure vulnerability. Attackers could use this vulnerability to collect data information and damage the system. | |
| Modificada | Media (5.3) | 0.86% | — | ZTE Zxcloud Goldendata VAP | 23/12/2019 | 17/6/2026 | All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information. | |
| Modificada | Media (6.5) | 0.89% | — | ZTE Zxcdn Iamweb Firmware | 22/11/2019 | 17/6/2026 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage. | |
| Modificada | Alta (7.2) | 1.1% | — | ZTE Zxcdn Iamweb Firmware | 22/11/2019 | 17/6/2026 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage. | |
| Modificada | Alta (8.2) | 0.92% | — | Ztehome C520v21 Firmware | 18/11/2019 | 17/6/2026 | authentication issues vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can automatically obtain access to web services from the authorized browser of the same computer and perform operations. | |
| Modificada | Media (5.3) | 1.3% | — | Ztehome C520v21 Firmware | 18/11/2019 | 17/6/2026 | permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources. | |
| Modificada | Media (6.5) | 0.73% | — | ZTE Zxhn H108n Firmware | 13/11/2019 | 17/6/2026 | All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations. | |
| Modificada | Alta (8.8) | 1.0% | — | ZTE Zxupn-9000e Firmware | 8/11/2019 | 17/6/2026 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations. | |
| Modificada | Alta (8.8) | 0.97% | — | ZTE Zxupn-9000e Firmware | 8/11/2019 | 17/6/2026 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts. | |
| Modificada | Media (6.2) | 0.95% | — | ZTE Mf910s Firmware | 7/11/2019 | 17/6/2026 | The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in… | |
| Modificada | Media (5.7) | 0.52% | — | ZTE Zxmp M721 DX Firmware | 31/10/2019 | 17/6/2026 | A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service. | |
| Modificada | Crítica (9.8) | 1.1% | — | ZTE Zxv10 B860a Firmware | 23/9/2019 | 17/6/2026 | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system. | |
| Modificada | Media (5.4) | 0.72% | — | ZTE Zxhn F670 Firmware | 15/8/2019 | 17/6/2026 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts. | |
| Modificada | Alta (8.8) | 1.9% | — | ZTE Zxhn F670 Firmware | 15/8/2019 | 17/6/2026 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system. | |
| Modificada | Media (4.8) | 0.49% | — | ZTE Otcp Firmware | 22/7/2019 | 17/6/2026 | All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process… | |
| Modificada | Media (5.7) | 0.88% | — | ZTE Zxmw Nr8000 Firmware | 11/7/2019 | 17/6/2026 | ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files. | |
| Modificada | Media (5.4) | 0.62% | — | ZTE Netnumen DAP Firmware | 11/6/2019 | 17/6/2026 | All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked. | |
| Modificada | Crítica (9.8) | 2.9% | — | ZTE Mf920 Firmware | 11/6/2019 | 17/6/2026 | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces. | |
| Modificada | Alta (7.5) | 1.3% | — | ZTE Mf920 Firmware | 11/6/2019 | 17/6/2026 | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components. | |
| Modificada | Alta (8.8) | 0.45% | — | ZTE Wf820+ LTE Outdoor CPE Firmware | 11/6/2019 | 17/6/2026 | All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this vulnerability to send unexpected… |