Impact
The vulnerability exists as a command injection flaw that allows an unauthenticated attacker to execute arbitrary system commands. By doing so, the attacker can delete critical runtime files, causing the monitoring module to crash, and can then gain root access to the device. Root privileges enable the attacker to read configuration files and modify SNMP passwords, potentially compromising the integrity and availability of the entire power system.
Affected Systems
Affected systems are ZTE ZXDU68 S202 routers running firmware version V5.0. The product is managed via the ZTE management interface, which the exploit targets. No other firmware versions are mentioned in the advisory.
Risk and Exploitability
The CVSS base score of 9.6 indicates a high severity, and pre‑exploit risk is significant though the EPSS data is missing. The vulnerability is not yet listed in CISA's KEV catalog, so no known active exploitation is reported. The attack vector is likely remote, through the exposed management interface, and requires no authentication, making it trivially exploitable in an unprotected network.
OpenCVE Enrichment