CVE-2025-53558
78Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.7epss 1.4%
from disclosure to weapon133 days
Published on NVDJul 31
1st PoC+133d
VulnCheck+273d
exploitation probability
1.4%top 31% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short
ZTE routers (ZXHN-F660T and ZXHN-F660A) come with the same default login credentials for all units. An attacker who knows these credentials can access and control any of these devices.
Technical detail
The affected ZTE router models use hardcoded or unchangeable default credentials across all installations, allowing unauthenticated remote attackers to gain administrative access via the management interface. This enables complete device compromise including configuration modification, traffic interception, and potential lateral network movement.
Summary generated and translated by AI from the official description.
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
public PoCs found — 1
vulncheckvulncheck.com/xdb/3a0d6f7fd10funverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://jvn.jp/en/jp/JVN66546573/