There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mf258k_pro_firmware | Zte | zte_mf258kpro_play_v1.0.0b03 (including) | zte_mf258kpro_play_v1.0.0b03 (including) |
| Mf258k_pro_firmware | Zte | zte_mf258pro_std_v1.0.0b04 (including) | zte_mf258pro_std_v1.0.0b04 (including) |