There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
2024-10-29T02:15:06.933
2025-01-28T17:13:43.877
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | zte | mf258k_pro_firmware | 1.0.0b03 | Yes |
| Hardware | zte | mf258k_pro | - | No |