ZTE ZXUniPOS NDS-LTE是中国中兴通讯(ZTE)公司的一款运营商网络定位平台。 ZTE ZXUniPOS NDS-LTE存在安全漏洞,该漏洞源于跨站请求伪造,可能导致攻击者利用用户已认证会话伪造跨站请求,诱导执行意外操作如篡改配置数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZTE | ZXUniPOS NDS-LTE | Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01) |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZTE | ZXUniPOS NDS-LTE | Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49002 | 9.1 CRITICAL | Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-49000 | 7.0 HIGH | Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-48999 | 5.7 MEDIUM | Stored Cross-Site Scripting (XSS) vulnerability in ZTE ZXUniPOS NDS-LTE product |
No comments yet