Vulnerabilities (CVE)

Filtered by vendor Zte Subscribe
Filtered by product Zxv10 W300 Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-4155 1 Zte 2 Zxv10 W300, Zxv10 W300 Firmware 2014-07-18 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.
CVE-2014-4154 1 Zte 2 Zxv10 W300, Zxv10 W300 Firmware 2014-07-16 5.0 MEDIUM N/A
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.
CVE-2014-4018 1 Zte 2 Zxv10 W300, Zxv10 W300 Firmware 2014-07-16 7.8 HIGH N/A
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.