MF286R Firmware
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for MF286R Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
MF286R Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium4
Latest CVEs
The 6 most recently published vulnerabilities affecting MF286R Firmware.
- CVE-2023-25651SQL Injection Vulnerability in Some ZTE Mobile Internet Products4.3
- CVE-2023-25649OS Command Injection Vulnerability in a Mobile Internet Product of ZTE6.8
- CVE-2022-39073There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.9.8
- CVE-2022-39072There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vu...5.4
- CVE-2022-39067There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denia...6.5
- CVE-2022-39066There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to exe...8.8
Product grouping is registry-driven, with AI assist and human review. How it works