ZeroHour

Vulnerabilities

174 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44409
There is an an information disclosure vulnerability in ZTE MU5250.

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

NVD description · AI analysis pending
7.5<1%
  • zte mu5250 firmware
CVE-2026-44406
+2 in the same advisory: …40004 …44407
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability;

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.

NVD description · AI analysis pending
7.8
group max
<1%
  • zte zxcloud irai
CVE-2026-40003
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB.

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

NVD description · AI analysis pending
6.8<1%
  • zte zx297520v3 firmware
CVE-2026-40002
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations.

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties.

NVD description · AI analysis pending
8.8<1%
  • zte nubia-in nx809j firmware
CVE-2026-40436
The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to th

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.

NVD description · AI analysis pending
7.5<1%
  • zte zxesm iems
CVE-2026-34472
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local ne

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK, and PPPoE credentials. In some observed cases, configuration changes may also be performed without authentication.

NVD description · AI analysis pending
7.19%
  • zte zxhn h188a firmware
CVE-2025-66315
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products.

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

NVD description · AI analysis pending
8.8<1%
  • zte mf258k pro firmware
CVE-2025-46579
There is a DDE injection vulnerability in the GoldenDB database product.

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

NVD description · AI analysis pending
7.8
group max
<1%
  • zte zxcloud goldendb
CVE-2025-26702
+4 in the same advisory: …26705 …26706 …26703 …26704
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB:

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

NVD description · AI analysis pending
7.5
group max
<1%
  • zte goldendb
CVE-2024-22063
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability.

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.

NVD description · AI analysis pending
9.0<1%
  • zte zenic one r58
CVE-2024-22067
ZTE NH8091 product has an improper permission control vulnerability.

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

NVD description · AI analysis pending
8.8<1%
  • zte nh8091 firmware
CVE-2024-22066
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router .

There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.

NVD description · AI analysis pending
6.5<1%
  • zte zxr10 1800-2s firmware
  • zte zxr10 2800-4 firmware
  • zte zxr10 3800-8 firmware
  • +1 more
CVE-2024-22065
There is a command injection vulnerability in ZTE MF258 Pro product.

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

NVD description · AI analysis pending
8.81%
  • zte mf258k pro firmware
CVE-2024-10119
The wireless router WRTM326 from SECOM does not properly validate a specific parameter.

The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.

NVD description · AI analysis pending
9.8<1%
  • zte wrtm326 firmware
CVE-2024-22068
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This i

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.

NVD description · AI analysis pending
6.5<1%
  • zte zxr10 1800-2s firmware
  • zte zxr10 2800-4 firmware
  • zte zxr10 3800-8 firmware
  • +1 more
CVE-2022-39068
There is a buffer overflow vulnerability in ZTE MF296R.

There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.

NVD description · AI analysis pending
6.5<1%
  • zte mf296r firmware
CVE-2024-22069
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and chan

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

NVD description · AI analysis pending
8.8<1%
  • zte zxv10 et301 firmware
  • zte zxv10 xt802 firmware
CVE-2024-22062
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by mo

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

NVD description · AI analysis pending
8.8<1%
  • zte zxcloud irai
CVE-2023-25646
There is an unauthorized access vulnerability in ZTE H388X.

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

NVD description · AI analysis pending
6.4<1%
  • zte zxhn h388x firmware
CVE-2024-22064
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.

NVD description · AI analysis pending
6.5<1%
  • zte zxun-epdg
CVE-2023-41781
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258.

There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

NVD description · AI analysis pending
6.1<1%
  • zte mf258 firmware
CVE-2023-41782
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulner

There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

NVD description · AI analysis pending
4.8<1%
  • zte zxcloud irai
CVE-2023-41784
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

NVD description · AI analysis pending
5.5<1%
  • zte redmagic 8 pro firmware
CVE-2023-41783
+3 in the same advisory: …41780 …41776 …41779
There is a command injection vulnerability of ZTE's ZXCLOUD iRAI.

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.

NVD description · AI analysis pending
7.8
group max
<1%
  • zte zxcloud irai
CVE-2023-4674
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commer

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
<1%
  • yaztekteknoloji e-commerce
CVE-2023-25643
+2 in the same advisory: …25644 …25642
There is a command injection vulnerability in some ZTE mobile internet products.

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

NVD description · AI analysis pending
8.8
group max
2%
  • zte mc801a firmware
  • zte mc801a1 firmware
CVE-2023-25651
There is a SQL injection vulnerability in some ZTE mobile internet products.

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

NVD description · AI analysis pending
8.0<1%
  • zte mf833u1 firmware
  • zte mf286r firmware
CVE-2023-25648
+1 in the same advisory: …25650
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product.

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

NVD description · AI analysis pending
7.8
group max
<1%
  • zte zxcloud irai
CVE-2023-47755
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommerce Product Carousel Slider plugin <= 3.3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommerce Product Carousel Slider plugin <= 3.3.5 versions.

NVD description · AI analysis pending
6.1<1%
  • aazztech woocommerce product carousel slider
CVE-2023-25649
There is a command injection vulnerability in a mobile internet product of ZTE.

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

NVD description · AI analysis pending
8.82%
  • zte mf286r firmware
CVE-2023-25647
There is a permission and access control vulnerability in some ZTE mobile phones.

There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

NVD description · AI analysis pending
3.3<1%
  • zte axon 30 firmware
  • zte axon 40 pro firmware
  • zte axon 40 ultra firmware
  • +1 more
CVE-2023-25645
There is a permission and access control vulnerability in some ZTE AndroidTV STBs.

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.

NVD description · AI analysis pending
7.7<1%
  • zte up t2 4k firmware
  • zte zxv10 b866v2-h firmware
  • zte zxv10 b866v2 firmware
  • +1 more