8.8

CVE-2025-66315

ZTE MF258K Pro Version Server has a Configuration Defect Vulnerability

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Mf258k Pro Firmware Version zte_mf258kpro_play_v1.0.0b03
   Zte ≫ Mf258k Pro Version -
Zte ≫ Mf258k Pro Firmware Version zte_mf258pro_std_v1.0.0b04
   Zte ≫ Mf258k Pro Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.134
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@zte.com.cn 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/4891644183717871638
Vendor Advisory