CVE-2025-46581
Published: 14 October 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2025-46581 is a remote code execution (RCE) vulnerability stemming from an issue in the Apache Struts framework, affecting ZTE's ZXCDN product. This flaw, classified under CWE-94 (Improper Control of Generation of Code), carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity due to its high impact on confidentiality, integrity, and availability.
An unauthenticated attacker can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation allows remote command execution on the affected system, albeit with non-root privileges, potentially enabling unauthorized access, data exfiltration, or further system compromise.
Mitigation details are outlined in ZTE's security bulletin available at https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3747693852734546826, which security practitioners should consult for patching instructions and workarounds.
Details
- CWE(s)
MITRE ATT&CK Enterprise Techniques
Why these techniques?
CVE-2025-46581 is a critical unauthenticated RCE vulnerability in Apache Struts within ZTE's public-facing ZXCDN product, directly enabling exploitation of a public-facing application.