CVE-2023-25651: ZTE MF286R Firmware

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

Affected products

  • ZTE MF286R Firmware: version cr_lvwrgbmf286rv1.0.0b04 only
  • ZTE MF833U1 Firmware: version bd_mf833u1v1.0.0b01 only

Published 2023-12-14. Last modified 2026-06-17.