Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zte
Zte zxunipos Nds-lte |
|
| Vendors & Products |
Zte
Zte zxunipos Nds-lte |
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampering with configuration data. | |
| Title | Cross-Site Request Forgery (CSRF) vulnerability in ZTE ZXUniPOS NDS-LTE product | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-05-28T03:39:34.347Z
Reserved: 2026-05-27T01:01:53.326Z
Link: CVE-2026-49001
Updated: 2026-05-27T13:39:21.256Z
Status : Deferred
Published: 2026-05-27T08:16:44.460
Modified: 2026-06-17T10:55:26.760
Link: CVE-2026-49001
No data.
OpenCVE Enrichment
Updated: 2026-05-27T12:45:32Z