ZTE ZXUniPOS NDS-LTE是中国中兴通讯(ZTE)公司的一款运营商网络定位平台。 ZTE ZXUniPOS NDS-LTE存在安全漏洞,该漏洞源于攻击者精心构造恶意脚本并注入目标系统,当其他用户访问包含恶意内容的页面时脚本自动加载执行,可能导致窃取用户cookie、劫持会话权限和篡改页面内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZTE | ZXUniPOS NDS-LTE | Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01) |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZTE | ZXUniPOS NDS-LTE | Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49002 | 9.1 CRITICAL | Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-49000 | 7.0 HIGH | Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-49001 | 5.3 MEDIUM | Cross-Site Request Forgery (CSRF) vulnerability in ZTE ZXUniPOS NDS-LTE product |
No comments yet