CVE-2017-10935: ZTE ZXR10 1800-2s Firmware
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
Affected products
- ZTE ZXR10 1800-2s Firmware: before 3.00.40 (fixed in 3.00.40)
Published 2018-07-25. Last modified 2026-06-17.