Zte

Zxv10 W300 Firmware

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 59.44%
  • Veröffentlicht 20.02.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 02:09:20

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.

  • EPSS 16.74%
  • Veröffentlicht 24.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from...

  • EPSS 32.59%
  • Veröffentlicht 24.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

  • EPSS 33.34%
  • Veröffentlicht 24.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and pass...

  • EPSS 4.49%
  • Veröffentlicht 30.12.2015 05:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a dif...

Exploit
  • EPSS 6.63%
  • Veröffentlicht 16.07.2014 14:19:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.

Exploit
  • EPSS 10.26%
  • Veröffentlicht 16.07.2014 14:19:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 19.06.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/to...