Impact
A weakness in ZTE F689 firmware allows an attacker to extract the root password hash from unencrypted information embedded within the device software. The exposed hash is a credential that, if recovered, could enable full administrative control over the device. This vulnerability represents a pure information‐disclosure flaw and does not involve active code execution or privilege escalation beyond the acquisition of the hash.
Affected Systems
All ZTE F689 devices are potentially impacted. No specific firmware release dates or version numbers are listed in the advisory, so any firmware built with the current product line should be considered at risk until the vendor publishes a covered update.
Risk and Exploitability
The CVSS score of 2.4 indicates a low overall risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires that an adversary obtain the firmware image, which might be possible through local access to the device or via any exposed firmware download interface. Based on the description, it is inferred that once the firmware is captured, an attacker would need to use offline techniques to crack the hash; therefore, the primary control vector is the disclosure of the credential rather than an immediate remote exploit.
OpenCVE Enrichment