CVE-2023-25645: ZTE Up t2 4k Firmware
High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
Affected products
- ZTE Up t2 4k Firmware: version v84511302.1427 only
- ZTE ZXV10 b860h v5d0 Firmware: version v83011303.0049 only; version v83011303.0051 only; version v83011303.0053 only; version v83011303.0063 only; version v83011303.0069 only
- ZTE ZXV10 b866v2-H Firmware: version v84711321.0038 only; version v84711321.0040 only; version v84711321.0045 only; version v84711321.0049 only
- ZTE ZXV10 b866v2 Firmware: version v82811306.3021 only; version v82815416.1027 only; version v82815416.1028 only; version v82815416.1029 only; version v82815416.2012 only; version v84711309.0016 only; …
- ZTE ZXV10 b866v2f Firmware: version v86111338.0026 only; version v86111338.0031 only; version v86111338.0033 only; version v86111338.0035 only
Published 2023-06-16. Last modified 2026-06-17.