CVE-2025-26708: ZTE Link

Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.

There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.

Affected products

  • ZTE ZTE Link: from 5.4.0, up to and including 5.4.9

Published 2025-03-07. Last modified 2026-06-17.