CVE-2023-25644: ZTE MC801A1 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

Affected products

  • ZTE MC801A1 Firmware: version mc801a1_elisa1_b04 only
  • ZTE MC801A Firmware: version mc801a_elisa3_b19 only

Published 2023-12-14. Last modified 2026-06-17.