ZTE Corporation
First CVE: Sep 19, 2017Active for: 9 years
173
CVEs Published
More CVEs Published than 77% of tracked CNAs
17.3
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by ZTE Corporation as a CNA, 89.0% affect products that ZTE Corporation develops as a vendor.
89.0%
11.0%
Self-reported: 154Third-party: 19
Of all the CVEs published that affect products developed by ZTE Corporation, 84.2% are self-published by ZTE Corporation as a CNA.
84.2%
15.8%
Self-published: 154Published by other CNAs: 29
Trends Over Time
The number and severity of CVEs published by ZTE Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2017
8 years ago
Most Recent CVE
May 27, 2026
58 days ago
Top CVEs
All CVEs published by ZTE Corporation as a CNA, regardless of affected vendor or product.
173 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7358HIGH ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized u | Nov 14, 2018 | 8.8 | 84 | NO | YES |
CVE-2018-7357HIGH ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized u | Nov 14, 2018 | 8.8 | 83 | NO | YES |
CVE-2021-21745MEDIUM ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations | Oct 20, 2021 | 4.3 | 57 | NO | YES |
CVE-2022-39066HIGH There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vul | Nov 22, 2022 | 8.8 | 40 | NO | NO |
CVE-2018-7364CRITICAL All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm pro | Dec 7, 2018 | 9.8 | 35 | NO | NO |
CVE-2026-49002CRITICAL Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, suc | May 27, 2026 | 9.1 | 33 | NO | NO |
CVE-2025-46581CRITICAL ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges. | Oct 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2022-39073CRITICAL There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary comma | Jan 6, 2023 | 9.8 | 32 | NO | NO |
CVE-2021-21748CRITICAL ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code. | Oct 20, 2021 | 9.8 | 32 | NO | NO |
CVE-2017-10934CRITICAL All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in | Jul 25, 2018 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA173 CVEs
43%
40%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local26 (15.0%)
Network120 (69.4%)
Unknown0 (0.0%)
Physical5 (2.9%)
Adjacent Network22 (12.7%)
Attack Complexity
Low169 (97.7%)
High4 (2.3%)
Unknown0 (0.0%)
User Interaction
None140 (80.9%)
Unknown0 (0.0%)
Required33 (19.1%)
Privileges Required
Low58 (33.5%)
High17 (9.8%)
None98 (56.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (173 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· 76th percentile
ExploitDB
4 CVEs
2.3% of CVEs· 90th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by ZTE Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ZTE Corporation as a CNA — matched by CVE ID, not by organization name.