There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
2024-10-29T02:15:06.933
2025-01-28T17:13:43.877
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | mf258k_pro_firmware | 1.0.0b03 | Yes |
Hardware | zte | mf258k_pro | - | No |