CVE-2024-22065: ZTE MF258K Pro Firmware

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

Affected products

  • ZTE MF258K Pro Firmware: version 1.0.0b03 only

Published 2024-10-29. Last modified 2026-06-17.