CVE-2025-26709

MEDIUM

ZTE F50 <F50_FLYMODEM_ZYV1.0.0B07 - Unauthenticated Sensitive Information Exposure

Title source: llm
STIX 2.1

Description

There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface

Scores

CVSS v3 5.7
EPSS 0.0004
EPSS Percentile 13.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
ZTE/F50 F50_FLYMODEM_ZYV1.0.0B07
Published Aug 15, 2025
Tracked Since Feb 18, 2026