Unauthorized Access Flaw in ZTE F50 Web Interface
CVE-2025-26709

5.7MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
15 August 2025

What is CVE-2025-26709?

An improper permission control vulnerability exists in the web interface of the ZTE F50. This flaw allows unauthorized attackers to exploit the interface, potentially accessing sensitive information without proper authorization. Organizations utilizing the ZTE F50 should assess their security measures to prevent exploitation of this vulnerability.

Affected Version(s)

F50 F50_FLYMODEM_ZYV1.0.0B07

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26709 : Unauthorized Access Flaw in ZTE F50 Web Interface