CVE-2015-7255: ZTE GAN9.8T101A-B Firmware

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.

Affected products

  • ZTE GAN9.8T101A-B Firmware: affected versions not specified
  • ZTE HG110 Firmware: affected versions not specified
  • ZTE MF28G Firmware: affected versions not specified
  • ZTE Ox-330p Firmware: affected versions not specified
  • ZTE w300v1.0.0s Zrd TR1 d68 Firmware: affected versions not specified
  • ZTE Zxhn h108n Firmware: affected versions not specified

Published 2017-08-29. Last modified 2026-06-17.