CVE-2024-22066: ZTE ZXR10 160 Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.

Affected products

  • ZTE ZXR10 160 Firmware: up to and including 3.00.40
  • ZTE ZXR10 1800-2s Firmware: up to and including 3.00.40
  • ZTE ZXR10 2800-4 Firmware: up to and including 3.00.40
  • ZTE ZXR10 3800-8 Firmware: up to and including 3.00.40

Published 2024-10-29. Last modified 2026-06-17.