CVE-2023-25642: ZTE MC801A1 Firmware

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

Affected products

  • ZTE MC801A1 Firmware: version mc801a1_elisa1_b04 only
  • ZTE MC801A Firmware: version mc801a_elisa3_b19 only

Published 2023-12-14. Last modified 2026-06-17.