Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 13% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 20/2/2020 | 17/6/2026 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0. | |
| Modificada | Alta (8.8) | 9.5% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs. | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin". | |
| Modificada | Media (6.5) | 4.9% | 💥 Exploit | ZTE Zxhn H108n R1A FirmwareZTE Zxv10 W300 Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | ZTE Zxv10 W300 FirmwareZTE Zxv10 W300 | 16/7/2014 | 17/6/2026 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js. | |
| Modificada | Alta (7.8) | 6.3% | 💥 Exploit | ZTE Zxv10 W300 FirmwareZTE Zxv10 W300 | 16/7/2014 | 17/6/2026 | The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | ZTE Zxv10 W300 FirmwareZTE Zxv10 W300 | 19/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1. |