CVE-2024-22063: ZTE Zenic One r58

Critical severity, CVSS 9.0. EPSS: 0.8% chance of exploitation in the next 30 days.

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.

Affected products

  • ZTE Zenic One r58: before 16.24.40 (fixed in 16.24.40)

Published 2024-12-30. Last modified 2026-06-17.