CVE-2025-46581: ZTE ZXCDN product has a Struts RCE Vulnerability
Published Oct 14, 2025
·Updated
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
Affected Software
1 affected component
ZTE ZXCDN
Event History
Oct 14, 2025
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46581?
CVE-2025-46581 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-46581?
To fix CVE-2025-46581, apply the latest patches provided by ZTE for the ZXCDN product.
3
Who can exploit CVE-2025-46581?
An unauthenticated attacker can exploit CVE-2025-46581 to execute commands remotely.
4
What are the potential impacts of CVE-2025-46581?
Exploitation of CVE-2025-46581 can lead to unauthorized command execution on affected systems.
5
Is CVE-2025-46581 an issue across all versions of ZXCDN?
CVE-2025-46581 affects the ZTE ZXCDN product, but specific impacted versions should be confirmed through ZTE's security advisories.