CVE-2023-25646: ZTE Zxhn h388x Firmware

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

Affected products

  • ZTE Zxhn h388x Firmware: version 10.1_agzhm_1.3.1 only

Published 2024-06-20. Last modified 2026-06-17.