CVE-2025-66315

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:zte:mf258k_pro_firmware:zte_mf258kpro_play_v1.0.0b03:*:*:*:*:*:*:*
cpe:2.3:o:zte:mf258k_pro_firmware:zte_mf258pro_std_v1.0.0b04:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf258k_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-09 03:15

Updated : 2026-03-12 19:26


NVD link : CVE-2025-66315

Mitre link : CVE-2025-66315

CVE.ORG link : CVE-2025-66315


JSON object : View

Products Affected

zte

  • mf258k_pro_firmware
  • mf258k_pro
CWE
CWE-269

Improper Privilege Management

CWE-863

Incorrect Authorization