CVE-2014-4019: ZTE ZXV10 w300 Firmware
High severity, CVSS 7.5. EPSS: 12.7% chance of exploitation in the next 30 days.
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.
Affected products
- ZTE ZXV10 w300 Firmware: version w300v1.0.0a_zrd_lk only
Published 2020-02-20. Last modified 2026-06-17.