CVE-2023-25643: ZTE MC801A1 Firmware
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Affected products
- ZTE MC801A1 Firmware: version mc801a1_elisa1_b04 only
- ZTE MC801A Firmware: version mc801a_elisa3_b19 only
Published 2023-12-14. Last modified 2026-06-17.