CVE-2025-26709 – ZTE F50 Web Module Unauthorized Access Vulnerability

The following table lists the changes that have been made to the
CVE-2025-26709 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 15, 2025

    Action Type Old Value New Value
    Added Description There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface
    Added CVSS V3.1 AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    Added CWE CWE-200
    Added Reference https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/1288700446535356789
Share the Post:

Related Posts