CVE-2023-25646

HIGH

ZTE H388X - Privilege Escalation

Title source: llm

Description

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

Scores

CVSS v3 7.1
EPSS 0.0010
EPSS Percentile 26.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-281
Status published

Affected Products (1)

zte/zxhn_h388x_firmware

Timeline

Published Jun 20, 2024
Tracked Since Feb 18, 2026