CVE-2024-45414: ZTE Zxhn e1600 Firmware
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.
Affected products
- ZTE Zxhn e1600 Firmware: version V1.0.0.2B1.1000 only
- ZTE Zxhn e2603 Firmware: version V1.0.1 only
- ZTE Zxhn e2615 Firmware: version V1.0.1 only
- ZTE Zxhn e2618 Firmware: version V1.0.0.2B4.3000 only
- ZTE Zxhn e500 Firmware: version V1.0.1.1B2.1000 only
- ZTE Zxhn h108n Firmware: version V2.6.20.ROST12 only
- ZTE Zxhn h168a Firmware
- ZTE Zxhn h168n Firmware: version V3.5.5_CO.1T1 only
- ZTE Zxhn h338a Firmware: version V1.5.0_H3A.1T9P1-o only
- ZTE Zxhn z500 Firmware: version V1.0.1.1B2.1000 only
Published 2024-09-16. Last modified 2026-06-17.