Impact
The vulnerability allows an attacker to retrieve unencrypted initial login credentials from the ZTE F689 device firmware. This direct exposure of administrator credentials enables compromised parties to gain control of the device’s web interface, potentially allowing full administrative access, configuration changes, or exploitation of other component weaknesses. The primary weakness is an insecure default credential storage, identified as CWE‑798.
Affected Systems
The affected system is the ZTE F689 router. No specific firmware version information is provided, so all implementations of this product should be considered vulnerable until a patch or updated firmware is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. EPSS information is not available, so the exact probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access to the device’s firmware or web interface; however, this inference is drawn from the fact that the credentials are obtainable via network communication with the device, and is not explicitly stated in the data.
OpenCVE Enrichment