A private key disclosure vulnerability exists in ZTEs ZXMP M721 product. A low-privileged user can bypass authorization checks to view the devices communication private key, resulting in key exposure and impacting communication security.
The product uses a hard-coded, unchangeable cryptographic key.