VendorsZTEzxv10_w300_firmware1.0.0a_zrd_lk
Vulnerabilities

ZTE ZXV10 W300 1.0.0a_zrd_lk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2014-4018
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Published 2014-07-16 · Modified
7.81 PoCEPSS 0.063
CVE-2014-4155
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.
Published 2014-06-19 · Modified
6.81 PoCEPSS 0.023
CVE-2014-4154
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.
Published 2014-07-16 · Modified
5.01 PoCEPSS 0.066