CVE-2025-46583
BaseFortify
Publication date: 2025-10-27
Last updated on: 2025-10-27
Assigner: ZTE Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zte | mc889a_pro | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-116 | The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Denial of Service (DoS) issue in the ZTE MC889A Pro product. It occurs because the product does not properly validate input parameters in its Short Message Service (SMS) interface. An attacker can exploit this flaw by sending specially crafted inputs to cause the system to become unavailable or crash.
How can this vulnerability impact me? :
The vulnerability can lead to a Denial of Service condition, meaning the affected device or service could become unavailable or unresponsive. This could disrupt communication services relying on the ZTE MC889A Pro, potentially causing operational downtime or loss of service.