CVE-2017-10930: ZTE ZXR10 160 Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.

Affected products

  • ZTE ZXR10 160 Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 1800-2s Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 2800-4 Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 3800-8 Firmware: before 3.00.40 (fixed in 3.00.40)

Published 2017-09-19. Last modified 2026-06-17.