CVE-2025-66314 – ZTE ElasticNet UME R32 ACL Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-66314 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Nov. 27, 2025

    Action Type Old Value New Value
    Added Description Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    Added CWE CWE-269
    Added Reference https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2180460616364429350
Share the Post:

Related Posts