CVE-2015-0974: Mobilis Mobiconnect

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediaplayerdll.dll.

Affected products

  • Mobilis Mobiconnect: version 1.0.0b03 only

Published 2017-08-28. Last modified 2026-06-17.