CVE-2025-26711

MEDIUM

ZTE T5400 <CR_UNIAGT5400V1.0.0B02 - Unauthenticated Sensitive Information Exposure

Title source: llm
STIX 2.1

Description

There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface.

Scores

CVSS v3 5.7
EPSS 0.0003
EPSS Percentile 8.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
ZTE/T5400 CR_UNIAGT5400V1.0.0B02
Published Sep 16, 2025
Tracked Since Feb 18, 2026