CVE-2025-53558

8.8

ZTE · ZXHN-F660T, ZXHN-F660A

ZTE ZXHN-F660T and ZXHN-F660A devices utilize hardcoded default credentials across all installations, allowing unauthenticated attackers to gain unauthorized access to the affected hardware.

Executive summary

A critical vulnerability involving the use of hardcoded credentials in ZTE ZXHN-F660T and ZXHN-F660A devices allows unauthenticated remote attackers to compromise affected units.

Vulnerability

The device uses a common, hardcoded credential for all installations, which permits an unauthenticated attacker to bypass authentication mechanisms entirely and gain administrative access to the device.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected networking equipment. This can lead to complete loss of confidentiality and integrity for traffic passing through the device, potential network interception, and long-term persistence within the local network environment. With a CVSS score of 8.8, this vulnerability represents a high-severity risk that requires immediate remediation to prevent unauthorized infrastructure control.

Remediation

Immediate Action: Update the firmware of the affected ZXHN-F660T and ZXHN-F660A devices to versions V1.0.10P17N4 and V1.0.10P14N4 respectively, as provided by the vendor.

Proactive Monitoring: Review device access logs for unauthorized login attempts and monitor for anomalous traffic patterns originating from or traversing the affected network hardware.

Compensating Controls: Restrict management interface access to trusted administrative IP addresses via firewall rules and isolate these devices from public-facing network segments to minimize exposure.

Exploitation status

Public Exploit Available: No (a Nuclei detection template exists, but no weaponized exploit or public proof-of-concept has been confirmed).

Analyst recommendation

Given the severity of this credential management failure and the potential for total device takeover, administrators must prioritize the application of the vendor-supplied firmware updates. Ensuring that these devices are not reachable from untrusted networks is a necessary secondary measure to prevent exploitation until patching is complete.

More ZTE CVEs

Sources