CVE-2024-45416: ZTE Zxhn e1600 Firmware
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid session file or not. An attacker who is able to write a malicious file in the sessions directory can get RCE as root.
Affected products
- ZTE Zxhn e1600 Firmware: version V1.0.0.2B1.1000 only
- ZTE Zxhn e2603 Firmware: version V1.0.1 only
- ZTE Zxhn e2615 Firmware: version V1.0.1 only
- ZTE Zxhn e2618 Firmware: version V1.0.0.2B4.3000 only
- ZTE Zxhn e500 Firmware: version V1.0.1.1B2.1000 only
- ZTE Zxhn h108n Firmware: version V2.6.20.ROST12 only
- ZTE Zxhn h168a Firmware
- ZTE Zxhn h168n Firmware: version V3.5.5_CO.1T1 only
- ZTE Zxhn h338a Firmware: version V1.5.0_H3A.1T9P1-o only
- ZTE Zxhn z500 Firmware: version V1.0.1.1B2.1000 only
Published 2024-09-16. Last modified 2026-06-17.