CVE-2025-53558 Details
Description
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.
A vulnerability exists in the ZTE ZXHN-F660T and ZXHN-F660A Optical Network Units (ONUs) provided by ZTE Japan K.K. These devices use a common credential for all installations, allowing an attacker with knowledge of the credential to log in to the affected devices. This vulnerability affects ZXHN-F660T firmware versions prior to V1.0.10P17N4 and ZXHN-F660A firmware versions prior to V1.0.10P14N4.
Users are advised to update the firmware to the latest version available from the developer. The fixed firmware invalidates the common credential.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2025CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN66546573/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ZTE ZXHN-F660T | All versions |
CPE
Remediation
| |
| ZTE ZXHN-F660A | < V1.0.10P17N4 < V1.0.10P14N4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | New CVE Received | [email protected] |
Volerion