Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.19% | — | ZTE U30 AIRAI | 30/9/2026 | 30/9/2026 | There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information. | |
| Aplazada | Media (6.2) | 0.20% | — | ZTE SmartlifeAI | 20/9/2026 | 22/9/2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. | |
| Aplazada | Baja (3.9) | 0.21% | — | ZTE Smart LifeAI | 5/8/2026 | 26/8/2026 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy… | |
| Aplazada | Baja (1.8) | 0.20% | — | ZTE File ManagerAI | 27/7/2026 | 28/7/2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level… | |
| Aplazada | Baja (2.1) | 0.25% | — | Zilliztech Deep-searcherAI | 7/6/2026 | 23/7/2026 | A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (1.1) | 0.07% | — | Zilliztech GptcacheAI | 4/6/2026 | 22/7/2026 | A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. Performing a manipulation of the argument input_data["image"] results in use of weak hash. The attack must be initiated… | |
| Aplazada | Baja (2.1) | 1.1% | — | Hiraishikentaro Wezterm MCPAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation of the argument request.params.arguments.pane_id leads to os command injection. The attack can be… | |
| Analizada | Alta (7.5) | 0.40% | — | ZTE Mu5250 Firmware | 22/5/2026 | 23/7/2026 | There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure. | |
| Aplazada | Media (6.3) | 0.35% | — | ZTE Mu5250AI | 19/5/2026 | 24/7/2026 | There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface. | |
| Analizada | Alta (7.5) | 0.32% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service. | |
| Analizada | Alta (7.8) | 0.20% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs… | |
| Analizada | Alta (7.8) | 0.17% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | |
| Analizada | Media (6.8) | 0.25% | — | ZTE Zx297520v3 Firmware | 7/5/2026 | 17/6/2026 | ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure… | |
| Pendiente de análisis | Alta (7.5) | 2.1% | — | ZTE Zxhn H298aAIZTE Zxhn H108nAI | 6/5/2026 | 17/6/2026 | Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authentication bypass and… | |
| Pendiente de análisis | Alta (7.5) | 1.9% | — | ZTE H8102eAIZTE H168nAIZTE H167aAIZTE H199aAI+13 | 6/5/2026 | 17/6/2026 | Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering,… | |
| Pendiente de análisis | Media (5.2) | 0.18% | — | ZTE Process GuardAI | 6/5/2026 | 17/6/2026 | There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traversal bypass. | |
| Analizada | Alta (8.8) | 0.15% | — | ZTE Nubia-in Nx809j Firmware | 17/4/2026 | 8/7/2026 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set… | |
| Analizada | Alta (7.5) | 0.35% | — | ZTE Zxesm Iems | 13/4/2026 | 17/6/2026 | The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained… | |
| Modificada | Alta (7.1) | 2.3% | — | ZTE Zxhn H188a Firmware | 30/3/2026 | 17/6/2026 | Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK, and PPPoE… | |
| Analizada | Alta (8.8) | 0.26% | — | ZTE Mf258k PRO Firmware | 9/1/2026 | 17/6/2026 | There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory. | |
| Aplazada | Media (6.9) | 0.42% | — | Kztech Jt3500v 4G LTE CPEAI | 31/12/2025 | 17/6/2026 | KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms. | |
| Aplazada | Alta (7.5) | 0.28% | — | ZTE Elasticnet UME R32AI | 27/11/2025 | 17/6/2026 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04. | |
| Aplazada | Media (5.3) | 0.43% | — | ZTE Mc889a PROAI | 27/10/2025 | 17/6/2026 | There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack. | |
| Aplazada | Alta (7.7) | 0.34% | — | ZTE Zxmp M721AI | 27/10/2025 | 17/6/2026 | A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user can bypass authorization checks to view the device's communication private key, resulting in key exposure and impacting communication security. | |
| Aplazada | Crítica (9.8) | 0.80% | — | ZTE ZxcdnAIApache StrutsAI | 14/10/2025 | 17/6/2026 | ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges. |