China Mobile's vulnerability footprint centers on a narrow range of residential gateway and intelligent home-network products, including the AN Lianbao WF series, which despite limited product count occupy a prominent position in the Chinese IoT and home-networking landscape. Vulnerabilities affecting these devices skew strongly toward critical severity and recur through command-injection and cross-site-scripting weaknesses endemic to embedded web interfaces with insufficient input sanitization, along with session-fixation issues in authentication handling. Defenders should prioritize these gateway devices in inventory scans, particularly where exposed to untrusted networks; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chinamobile over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20326MEDIUM ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter. | Jan 2, 2019 | 6.1 | 33 | NO | YES |
CVE-2021-33963CRITICAL China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injecti | Jan 15, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-30230CRITICAL The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonena | Apr 29, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-41011CRITICAL Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_ | Sep 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-30233CRITICAL The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan pa | Apr 29, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-30232CRITICAL The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROX | Apr 29, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-30228CRITICAL The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlin | Apr 29, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-41012CRITICAL An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. | Sep 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-30234CRITICAL The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_ | Apr 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-30231CRITICAL The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiad | Apr 29, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chinamobile.
Media articles that mention a CVE ID that affects a product developed by Chinamobile — matched by CVE ID, not by vendor name.