This page lists publicly disclosed CVE vulnerabilities affecting zte mf258k_pro_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-66315 | There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory. | [email protected] | 4.3 | 0.22% | 2026-01-08 | 2026-06-17 |
| CVE-2024-22065 | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | [email protected] | 6.8 | 1.16% | 2024-10-28 | 2026-06-17 |