Medium severity6.8NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-22065
CVE-2024-22065
Description
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Affected products
3- cpe:2.3:o:zte:mf258k_pro_firmware:1.0.0b03:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: ZTE_MF258PRO_STD_V1.0.0B03
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.