ZTE USA's vulnerability profile centers on a small portfolio of mobile handsets and related firmware, including the ZMax Champ, Blade Spark, and Blade Vantage product lines. The observed weakness classes recur across web-application and information-handling domains, including cross-site request forgery, cross-site scripting, authorization gaps, and sensitive-information leakage in logs, consistent with the mobile-device management and web-interface attack surface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zteusa over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15005HIGH The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package | Dec 28, 2018 | 7.1 | 23 | NO | NO |
CVE-2014-9027MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that disable modem | Nov 20, 2014 | 6.8 | 20 | NO | NO |
CVE-2018-15006MEDIUM The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package | Dec 28, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-14995MEDIUM The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fing | Dec 28, 2018 | 4.7 | 18 | NO | NO |
CVE-2014-9021MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr | Nov 20, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zteusa.
Media articles that mention a CVE ID that affects a product developed by Zteusa — matched by CVE ID, not by vendor name.