CVE Vulnerabilities

CVE-2025-66315

Improper Privilege Management

Published: Jan 09, 2026 | Modified: Mar 12, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Mf258k_pro_firmwareZtezte_mf258kpro_play_v1.0.0b03 (including)zte_mf258kpro_play_v1.0.0b03 (including)
Mf258k_pro_firmwareZtezte_mf258pro_std_v1.0.0b04 (including)zte_mf258pro_std_v1.0.0b04 (including)

Potential Mitigations

References