Home

Description

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.

PUBLISHED Reserved 2026-05-06 | Published 2026-05-19 | Updated 2026-05-19 | Assigner zte




MEDIUM: 6.3CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Problem types

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

BD_FLYMODEMMU5250V1.0.0B27
affected

Credits

Duc Anh Nguyen from NTCS&TinyxLab finder

References

support.zte.com.cn/...ui/bulletin/detail/2657904255874650158

cve.org (CVE-2026-44408)

nvd.nist.gov (CVE-2026-44408)

Download JSON