CVE-2017-10930: ZTE ZXR10 160 Firmware
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
Affected products
- ZTE ZXR10 160 Firmware: before 3.00.40 (fixed in 3.00.40)
- ZTE ZXR10 1800-2s Firmware: before 3.00.40 (fixed in 3.00.40)
- ZTE ZXR10 2800-4 Firmware: before 3.00.40 (fixed in 3.00.40)
- ZTE ZXR10 3800-8 Firmware: before 3.00.40 (fixed in 3.00.40)
Published 2017-09-19. Last modified 2026-06-17.