CVE-2024-45415: ZTE Zxhn e1600 Firmware
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.
Affected products
- ZTE Zxhn e1600 Firmware: version V1.0.0.2B1.1000 only
- ZTE Zxhn e2603 Firmware: version V1.0.1 only
- ZTE Zxhn e2615 Firmware: version V1.0.1 only
- ZTE Zxhn e2618 Firmware: version V1.0.0.2B4.3000 only
- ZTE Zxhn e500 Firmware: version V1.0.1.1B2.1000 only
- ZTE Zxhn h108n Firmware: version V2.6.20.ROST12 only
- ZTE Zxhn h168a Firmware
- ZTE Zxhn h168n Firmware: version V3.5.5_CO.1T1 only
- ZTE Zxhn h338a Firmware: version V1.5.0_H3A.1T9P1-o only
- ZTE Zxhn z500 Firmware: version V1.0.1.1B2.1000 only
Published 2024-09-16. Last modified 2026-06-17.