CVE-2017-10931: ZTE ZXR10 160 Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.

Affected products

  • ZTE ZXR10 160 Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 1800-2s Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 2800-4 Firmware: before 3.00.40 (fixed in 3.00.40)
  • ZTE ZXR10 3800-8 Firmware: before 3.00.40 (fixed in 3.00.40)

Published 2017-09-19. Last modified 2026-06-17.