CVE-2025-53558 describes a critical vulnerability in ZTE Japan K.K.'s ZXHN-F660T and ZXHN-F660A devices, where all installations share a common, hardcoded credential. This allows an unauthenticated attacker on the adjacent network to log in and gain full control of the device, leading to high impact on confidentiality, integrity, and availability. Rated 8.8 HIGH on CVSS, this vulnerability is not yet in CISA's KEV catalog, but a Nuclei template for default credential exploitation exists, and it has garnered significant community discussion with 15 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ZTE Japan. K.K. | ZXHN-F660A | prior to V1.0.10P14N4CNA affected | |
| ZTE Japan. K.K. | ZXHN-F660T | prior to V1.0.10P17N4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.