CVE-2023-25649: ZTE MF286R Firmware

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

Affected products

  • ZTE MF286R Firmware: version cr_lvwrgbmf286rv1.0.0b04 only

Published 2023-08-25. Last modified 2026-06-17.