Brand profile · models not graded yet

Is ZTE Router Safe?

ZTE is a Chinese telecom maker on the FCC Covered List since 2021 and barred from US federal procurement. Ownership, CVEs and updates explained.

Last reviewed: October 2026 · ismyroutersafe.com

Ownership & FCC Status
Owner
ZTE Corporation (Shenzhen, China; listed in Shenzhen and Hong Kong)
FCC Status
On the FCC Covered List: no new equipment authorizations
Ban Status
Named on the FCC Covered List since March 2021
Manufacturing
China
Models graded
Not yet

Security Verdict

ZTE Corporation is a publicly listed Chinese telecom equipment maker headquartered in Shenzhen. As of 2018, state-owned groups were among the shareholders of its largest shareholder. ZTE equipment has been on the FCC Covered List since March 2021, so new ZTE equipment cannot get FCC authorization, and US federal agencies and contractors are barred from using it. ZTE routers, mostly supplied by ISPs and mobile operators, have had several critical and high-severity flaws since 2023. None are on CISA's exploited list, but a 2026 Mirai botnet campaign used an exploit for an older ZTE router.

Bottom line: ZTE equipment is on the FCC Covered List and barred from US federal use for national security reasons. If your ISP supplied a ZTE router, ask whether it is still supported and what replacement options exist.

Rio Router
From the team behind this checker
Weighing up ZTE? See the router that scores an A on this same method.
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site, and its router is graded by the same method as every other.

Corporate Ownership Structure

ZTE Corporation is headquartered in Shenzhen, China, and listed in Shenzhen (000063) and Hong Kong (0763). Its largest shareholder, ZTE Holdings, held about 20.29% in 2022, and state-owned aerospace group subsidiaries were among ZTE Holdings' shareholders per its 2018 annual report. ZTE pleaded guilty in 2017 to illegal exports to Iran and North Korea, with about US$1.19 billion in penalties, and settled a 2018 Commerce denial order with a US$1 billion fine plus US$400 million in escrow.

Key Risk Factors

Named on the FCC Covered List since 2021
Since March 12, 2021, telecommunications equipment produced by ZTE Corporation has been on the FCC Covered List, which blocks new FCC equipment authorizations. No ZTE router appears on the FCC Conditional Approvals list.
Barred from US federal use
Section 889 of the FY2019 NDAA, implemented in FAR 52.204-25, bars federal agencies and contractors from covered telecom equipment produced by Huawei or ZTE, effective August 13, 2019.
State-linked ownership
Per ZTE's 2018 annual report as cited by Wikipedia, the shareholders of its largest shareholder, ZTE Holdings, included subsidiaries of two Chinese state-owned aerospace groups, which nominated 5 of 9 ZTE Holdings directors.
Critical router flaws and botnet use
CVE-2024-45414 and CVE-2024-45415 (both CVSS 9.8) affect the web server of multiple ZTE routers. In April 2026, Akamai reported a Mirai botnet campaign that included an exploit for the ZTE ZXV10 H108L router.
End-of-support products are not patched
ZTE runs a product security team (PSIRT) that publishes bulletins, but its policy excludes end-of-service products from vulnerability handling.

Known CVEs - ZTE Routers

The following vulnerabilities from the NIST National Vulnerability Database affect ZTE router models. This is a representative sample; the full CVE list may be longer.

CVE-2024-45414 Critical (CVSS 9.8)
Stack overflow in the web server of multiple ZTE routers.
CVE-2024-45415 Critical (CVSS 9.8)
A second stack overflow in the web server of multiple ZTE routers.
CVE-2025-53558 High (CVSS 8.7)
ZXHN-F660T and F660A gateways from ZTE Japan use the same credential across all installations.
CVE-2026-34474 High (CVSS 7.5)
Admin and Wi-Fi credential leak in the ZXHN H298A and H108N gateways.

Frequently Asked Questions

ZTE routers carry two kinds of risk. ZTE is a Chinese company with state-linked shareholders, and the US government has named its equipment a security concern since at least 2019. Its routers have also had several critical flaws since 2023, and older models that reach end of support no longer get fixes. If you have one, check that it is still supported and keep it updated.

ZTE equipment has been on the FCC Covered List since March 2021, which means new ZTE equipment cannot get FCC authorization. US federal agencies and contractors have been barred from ZTE telecom equipment since 2019 under Section 889 of the NDAA. FCC guidance on the 2026 router rule says consumers may keep using routers they already own.

ZTE Corporation is listed on the Shenzhen and Hong Kong stock exchanges. Its largest shareholder, ZTE Holdings, held about 20% in 2022. Per ZTE's 2018 annual report as cited by Wikipedia, ZTE Holdings' shareholders included subsidiaries of two Chinese state-owned aerospace groups. Wikipedia describes ZTE as partially state-owned.

ZTE has a product security team (PSIRT) that publishes security bulletins and says it confirms reports within one working day. Products past end of service are excluded from vulnerability handling. How often consumer and ISP routers get updates is not publicly confirmed.

ZTE routers are mostly supplied by ISPs and mobile operators, such as the ZXHN fiber and DSL gateways and the MF-series 4G routers. Which US ISPs, if any, currently supply ZTE routers is not publicly confirmed.

Sources

Facts on this page come from these sources (publish date, or the date we checked the page).

CHECK YOUR SPECIFIC MODEL

Get your router's full security report

Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.

Check a Router → Top 10 Safe Routers
Most home routers have hidden risks. Rio Router is the only one we rate A. See why →