ZTE vendor intelligence

ZTE Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting ZTE products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse ZTE KEVs Full KEV feed
Total KEVs
2
Known exploited vulnerabilities affecting ZTE products
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
2
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
ZTE KEVs with sensor-observed exploitation activity

The catalog gap matters for ZTE exposure

Two of the two exploited ZTE CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.

0%
Covered by CISA
100%
Beyond CISA
2
Product families

Attested ZTE CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2014-2321

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated...

F460 and F660 cable modems High Beyond CISA 20 Aug 2025
CVE-2021-21745

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform...

MF971R High Beyond CISA 20 Oct 2021

Showing 2 of 2 ZTE known exploited vulnerabilities.

Recurring weakness patterns

Permissions, privileges, and access controls and cross-site request forgery (csrf) account for two mapped occurrences across this ZTE KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.