CVE-2025-66315: ZTE MF258K Pro Version Server has a Configuration Defect Vulnerability
Published Jan 9, 2026
·Updated
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.
Affected Software
4 affected components
ZTE MF258K Pro
All of the following
Any of the following
ZTE Mf258k Pro Firmware=zte_mf258kpro_play_v1.0.0b03
ZTE Mf258k Pro Firmware=zte_mf258pro_std_v1.0.0b04
ZTE MF258K Pro
Event History
Jan 9, 2026
CVE Published
via MITRE·02:24 AM
Data Sourced
via MITRE·02:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 30, 58165
Event
via NVD·10:48 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-66315?
CVE-2025-66315 is considered a high-severity vulnerability due to the potential for unauthorized write access in specific directories.
2
How do I fix CVE-2025-66315?
To fix CVE-2025-66315, ensure that directory permissions are correctly set to prevent unauthorized access.
3
What products are affected by CVE-2025-66315?
CVE-2025-66315 affects ZTE MF258K Pro products.
4
What type of vulnerability is CVE-2025-66315?
CVE-2025-66315 is a configuration defect vulnerability involving improper directory permission settings.
5
Can an attacker exploit CVE-2025-66315 remotely?
Yes, an attacker can exploit CVE-2025-66315 remotely by leveraging the improper directory permissions.