ZTE Corporation

First CVE: Sep 19, 2017Active for: 9 years
173
CVEs Published
More CVEs Published than 77% of tracked CNAs
17.3
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by ZTE Corporation as a CNA, 89.0% affect products that ZTE Corporation develops as a vendor.

89.0%
11.0%
Self-reported: 154Third-party: 19

Of all the CVEs published that affect products developed by ZTE Corporation, 84.2% are self-published by ZTE Corporation as a CNA.

84.2%
15.8%
Self-published: 154Published by other CNAs: 29

Trends Over Time

The number and severity of CVEs published by ZTE Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2017
8 years ago
Most Recent CVE
May 27, 2026
58 days ago

Top CVEs

All CVEs published by ZTE Corporation as a CNA, regardless of affected vendor or product.

173 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized u
Nov 14, 20188.884NOYES
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized u
Nov 14, 20188.883NOYES
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations
Oct 20, 20214.357NOYES
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vul
Nov 22, 20228.840NONO
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm pro
Dec 7, 20189.835NONO
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, suc
May 27, 20269.133NONO
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
Oct 14, 20259.832NONO
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary comma
Jan 6, 20239.832NONO
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
Oct 20, 20219.832NONO
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in
Jul 25, 20189.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA173 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local26 (15.0%)
Network120 (69.4%)
Unknown0 (0.0%)
Physical5 (2.9%)
Adjacent Network22 (12.7%)
Attack Complexity
Low169 (97.7%)
High4 (2.3%)
Unknown0 (0.0%)
User Interaction
None140 (80.9%)
Unknown0 (0.0%)
Required33 (19.1%)
Privileges Required
Low58 (33.5%)
High17 (9.8%)
None98 (56.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (173 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· 76th percentile
ExploitDB
4 CVEs
2.3% of CVEs· 90th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by ZTE Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ZTE Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs