CVE-2024-45416
- EPSS 0.16%
- Published 16.09.2024 21:15:46
- Last modified 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them u...
CVE-2024-45413
- EPSS 0.22%
- Published 16.09.2024 21:15:45
- Last modified 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking ...
CVE-2024-45414
- EPSS 0.83%
- Published 16.09.2024 21:15:45
- Last modified 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded c...
CVE-2024-45415
- EPSS 0.68%
- Published 16.09.2024 21:15:45
- Last modified 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request...
CVE-2021-21729
- EPSS 0.12%
- Published 13.04.2021 16:15:12
- Last modified 21.11.2024 05:48:53
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_B...
CVE-2019-3420
- EPSS 0.09%
- Published 13.11.2019 23:15:11
- Last modified 21.11.2024 04:42:03
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.
CVE-2015-7255
- EPSS 0.8%
- Published 29.08.2017 15:29:00
- Last modified 20.04.2025 01:37:25
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-mi...