Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · zte

zte

· 17 Critical

Total CVEs

181

Critical

17

Products

321

Search All CVEs →

181

Products (321)

zxcloud irai13 CVEszxv10 w30010 CVEszxv10 w300 firmware8 CVEszxhn f670 firmware7 CVEszxcloud goldendb7 CVEsmf971r firmware7 CVEsmf971r7 CVEszxhn f6707 CVEsmf286r6 CVEsmf286r firmware6 CVEszxhn h108n r1a firmware6 CVEszxhn h108n r1a6 CVEszxhn h168n5 CVEsgoldendb5 CVEszxr10 1800-2s5 CVEszxr10 1800-2s firmware5 CVEszxhn h168n firmware5 CVEszxr10 3800-84 CVEszxr10 2800-44 CVEszxr10 3800-8 firmware4 CVEsaxon 40 ultra4 CVEszxr10 2800-4 firmware4 CVEszxdsl4 CVEszxr10 1604 CVEszxr10 160 firmware4 CVEsaxon 40 ultra firmware4 CVEsmc801a1 firmware3 CVEsmc801a firmware3 CVEsblade v40 vita firmware3 CVEsblade v30 vita3 CVEszxhn h108n3 CVEszxhn h108n firmware3 CVEsblade a313 CVEsblade a31 firmware3 CVEsblade a52 firmware3 CVEsblade a5 20193 CVEsblade a31 plus3 CVEsblade a31 plus firmware3 CVEsv40 pro firmware3 CVEsv40 pro3 CVEsblade a5 2019 firmware3 CVEsblade a3 lite3 CVEsblade a5 20203 CVEsblade a3 lite firmware3 CVEsblade a513 CVEszxcloud goldendata vap3 CVEsblade a5 2020 firmware3 CVEsblade a713 CVEsblade a51 firmware3 CVEsblade a523 CVEsmc801a3 CVEsblade a71 firmware3 CVEsblade a723 CVEsblade a72 firmware3 CVEsblade v30 vita firmware3 CVEsblade a7s3 CVEsblade a7s firmware3 CVEsblade l2103 CVEsblade l210 firmware3 CVEsblade v20 smart3 CVEsblade v20 smart firmware3 CVEsblade v303 CVEsblade v30 firmware3 CVEsblade v40 vita3 CVEsmc801a13 CVEsmf258k pro2 CVEsmf920 firmware2 CVEse8820v32 CVEse8820v3 firmware2 CVEszxa10 c300m2 CVEszxa10 c300m firmware2 CVEszxin10 cms2 CVEszxiptv2 CVEsotcp2 CVEszxiptv firmware2 CVEszxmp m7212 CVEsotcp firmware2 CVEsox-330p2 CVEszxmp m721 firmware2 CVEsox-330p firmware2 CVEsr5300g42 CVEsr5300g4 firmware2 CVEsr5500g42 CVEsr5500g4 firmware2 CVEsr8500g42 CVEsr8500g4 firmware2 CVEsmf9202 CVEsmf258k pro firmware2 CVEszxcdn2 CVEswf820\+ lte outdoor cpe2 CVEswf820\+ lte outdoor cpe firmware2 CVEszxcdn iamweb2 CVEszxcdn iamweb firmware2 CVEszxupn-9000e2 CVEszxupn-9000e firmware2 CVEszxv10 b860a2 CVEszxv10 b860a firmware2 CVEszxdsl 831cii2 CVEszxhn e88102 CVEszxhn e8810 firmware2 CVEszxhn e88202 CVEszxhn e8820 firmware2 CVEszxhn e88222 CVEszxhn e8822 firmware2 CVEszxa10 f819 firmware1 CVEszxa10 f8211 CVEszxa10 f821 firmware1 CVEszxa10 f8221 CVEszxa10 f822 firmware1 CVEszxa10 f822p1 CVEszxa10 f822p firmware1 CVEszxa10 f8321 CVEszxa10 f832 firmware1 CVEszxa10 f832v21 CVEszxa10 f832v2 firmware1 CVEszxa10 f8391 CVEszxa10 f839 firmware1 CVEszxa10 s100v1 CVEszxa10 s100v firmware1 CVEszxa10 s200a1 CVEszxa10 s200a firmware1 CVEszxa10 s200t1 CVEszxa10 s200t firmware1 CVEszxcdn-sns1 CVEszxcdn-sns firmware1 CVEszxcdn firmware1 CVEszxctn 6120h1 CVEszxctn 6120h firmware1 CVEszxctn 65001 CVEszxctn 6500 firmware1 CVEszxdsl 8311 CVEszxdsl 831cii firmware1 CVEszxdt22 sf011 CVEszxdt22 sf01 firmware1 CVEszxen cg2001 CVEszxen cg200 firmware1 CVEszxesm iems1 CVEszxhn-h108ns1 CVEszxhn-h108ns firmware1 CVEszxhn f4771 CVEszxhn f477 firmware1 CVEszxhn f6231 CVEszxhn f623 firmware1 CVEszxhn f670l1 CVEszxhn f670l firmware1 CVEszxhn f6771 CVEszxhn f677 firmware1 CVEszxhn f6801 CVEszxhn f680 firmware1 CVEszxhn h108l1 CVEszxhn h108l firmware1 CVEszxhn h188a1 CVEszxhn h188a firmware1 CVEszxhn h196q1 CVEszxhn h196q firmware1 CVEszxhn h26401 CVEszxhn h2640 firmware1 CVEszxhn h388x1 CVEszxhn h388x firmware1 CVEszxhn hs5621 CVEszxhn hs562 firmware1 CVEszxhn z5001 CVEszxhn z500 firmware1 CVEszxin101 CVEszxiptv-epg1 CVEszxiptv-epg firmware1 CVEszxiptv-ucm1 CVEszxiptv-ucm firmware1 CVEszxmp m721 dx1 CVEszxmp m721 dx firmware1 CVEszxmw nr80001 CVEszxmw nr8000 firmware1 CVEszxone 197001 CVEszxone 19700 firmware1 CVEszxone 19700 snpe1 CVEszxone 19700 snpe firmware1 CVEszxone 87001 CVEszxone 8700 firmware1 CVEszxone 97001 CVEszxone 9700 firmware1 CVEszxr10 2800-4 almpufb\(low\)1 CVEszxr10 2800-4 almpufb\(low\) firmware1 CVEszxr10 8900e1 CVEszxr10 8900e firmware1 CVEszxr10 8905e1 CVEszxr10 8905e firmware1 CVEszxr10 99041 CVEszxr10 9904-s1 CVEszxr10 9904-s firmware1 CVEszxr10 9904 firmware1 CVEszxr10 99081 CVEszxr10 9908-s1 CVEszxr10 9908-s firmware1 CVEszxr10 9908 firmware1 CVEszxr10 99161 CVEszxr10 9916 firmware1 CVEszxun-epdg1 CVEszxv10 b860av2.1 chinamobile1 CVEszxv10 b860av2.1 chinamobile firmware1 CVEszxv10 b860h v5.01 CVEszxv10 b860h v5.0 firmware1 CVEszxv10 b860h v5d01 CVEszxv10 b860h v5d0 firmware1 CVEszxv10 b866v21 CVEszxv10 b866v2-h1 CVEszxv10 b866v2-h firmware1 CVEszxv10 b866v2 firmware1 CVEszxv10 b866v2f1 CVEszxv10 b866v2f firmware1 CVEszxv10 et3011 CVEszxv10 et301 firmware1 CVEszxv10 m9101 CVEszxv10 m910 firmware1 CVEszxv10 w9081 CVEszxv10 w908 firmware1 CVEszxv10 xt8021 CVEsaxon 11 5g1 CVEszxv10 xt802 firmware1 CVEsaxon 11 5g firmware1 CVEsaxon 301 CVEsaxon 30 firmware1 CVEsaxon 30 pro message service1 CVEsaxon 40 pro1 CVEsaxon 40 pro firmware1 CVEsevdc1 CVEsf4601 CVEsf6601 CVEsf6801 CVEsf680 firmware1 CVEsf6x2w1 CVEsf6x2w firmware1 CVEsgan9.8t101a-b1 CVEsgan9.8t101a-b firmware1 CVEshg1101 CVEshg110 firmware1 CVEsmf2581 CVEsmf258 firmware1 CVEsmf289d1 CVEsmf289d firmware1 CVEsmf28g1 CVEsmf28g firmware1 CVEsmf296r1 CVEsmf296r firmware1 CVEsmf297d1 CVEsmf297d firmware1 CVEsmf651 CVEsmf65 firmware1 CVEsmf65m11 CVEsmf65m1 firmware1 CVEsmf833u11 CVEsmf833u1 firmware1 CVEsmf910s1 CVEsmf910s firmware1 CVEsnetnumen dap1 CVEsnetnumen dap firmware1 CVEsnetnumen u31 r101 CVEsnetnumen u31 r10 firmware1 CVEsnh80911 CVEsnh8091 firmware1 CVEsnr8000tr1 CVEsnr8000tr firmware1 CVEsnr81201 CVEsnr8120 firmware1 CVEsnr8120a1 CVEsnr8120a firmware1 CVEsnr81501 CVEsnr8150 firmware1 CVEsnr82501 CVEsnr8250 firmware1 CVEsnr89501 CVEsnr8950 firmware1 CVEsnubia z501 CVEsnubia z50 firmware1 CVEsoscp1 CVEsredmagic 8 pro1 CVEsredmagic 8 pro firmware1 CVEsscore m1 CVEsup t2 4k1 CVEsup t2 4k firmware1 CVEsusmartview1 CVEsw300v1.0.0s zrd tr1 d681 CVEsw300v1.0.0s zrd tr1 d68 firmware1 CVEswrtm3261 CVEswrtm326 firmware1 CVEszaip-aie1 CVEszenic one r22b1 CVEszenic one r581 CVEsztemarket apk1 CVEszx297520v31 CVEszx297520v3 firmware1 CVEszxa10 b700v71 CVEszxa10 b700v7 firmware1 CVEszxa10 b710c-a121 CVEszxa10 b710c-a12 firmware1 CVEszxa10 b710s2-a191 CVEszxa10 b710s2-a19 firmware1 CVEszxa10 b766v21 CVEszxa10 b766v2 firmware1 CVEszxa10 b76hv31 CVEszxa10 b76hv3 firmware1 CVEszxa10 b800v21 CVEszxa10 b800v2 firmware1 CVEszxa10 b836ct-a151 CVEszxa10 b836ct-a15 firmware1 CVEszxa10 b860av2.11 CVEszxa10 b860av2.1 firmware1 CVEszxa10 b860h1 CVEszxa10 b860h firmware1 CVEszxa10 b866v2-h1 CVEszxa10 b866v2-h firmware1 CVEszxa10 b866v5-w101 CVEszxa10 b866v5-w10 firmware1 CVEszxa10 b960gv11 CVEszxa10 b960gv1 firmware1 CVEszxa10 c350m1 CVEszxa10 c350m firmware1 CVEszxa10 eodn1 CVEszxa10 eodn firmware1 CVEszxa10 f8091 CVEszxa10 f809 firmware1 CVEszxa10 f8191 CVEs

Recent Vulnerabilities

View all 181
CVE-2026-44407MEDIUM 4.7

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

CVE-2026-44406MEDIUM 5.7

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.

CVE-2026-40004MEDIUM 5.5

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.

CVE-2026-40003MEDIUM 5.1

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

CVE-2026-40436HIGH 7.1

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.

CVE-2026-34472HIGH 7.1

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK, and PPPoE credentials. In some observed cases, configuration changes may also be performed without authentication.

CVE-2025-66315MEDIUM 4.3

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

CVE-2025-46580HIGH 7.7

There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL.

CVE-2025-46579HIGH 8.4

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

CVE-2025-46578MEDIUM 6.5

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.

CVE-2025-46577MEDIUM 6.5

There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

CVE-2025-46576MEDIUM 5.4

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.

CVE-2025-46575MEDIUM 4.9

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

CVE-2025-46574MEDIUM 4.1

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

CVE-2025-26706MEDIUM 5.4

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

CVE-2025-26705MEDIUM 5.3

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

CVE-2025-26704MEDIUM 6.4

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

CVE-2025-26703MEDIUM 4.3

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

CVE-2025-26702MEDIUM 4.9

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

CVE-2024-22063HIGH 7.6

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.

CVE-2024-22067MEDIUM 6.8

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

CVE-2024-22066HIGH 7.5

There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.

CVE-2024-22065MEDIUM 6.8

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVE-2024-10119CRITICAL 9.8

The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.

CVE-2024-22068MEDIUM 6.0

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.