External risk intelligence

ZTE ZXCDN Struts Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-46581

The vulnerability affects a Content Delivery Network (CDN) product, which is a component typically deployed at the edge of a network to manage traffic and delivery. Because such systems are designed to interface with external network traffic to perform their primary function, they are frequently positioned in internet-facing configurations.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in ZTE's ZXCDN product, specifically a remote code execution flaw within the Struts framework. This issue allows for unauthenticated remote command execution, potentially impacting the integrity and availability of services managed by this technology. The main concern at this time is to confirm whether our organization utilizes this specific product and, if so, to what extent it is exposed.

  • Struts flaw allows remote command execution.
  • Affects edge network devices managing traffic.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit a remote code execution vulnerability in ZTE's ZXCDN product by sending specially crafted network requests. This allows them to execute arbitrary commands on the affected system without needing any prior authentication or special privileges. Successful exploitation could lead to significant compromise of the system's integrity and confidentiality.

  • No authentication required.
  • Network-accessible vulnerable component.
  • Remote command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to remotely execute commands on the affected product when it is deployed in a network-facing configuration. This could impact the integrity and availability of the service, and potentially lead to the exposure of system data.

  • System data on the affected device.
  • Remote command execution.
  • Service disruption or compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for network edge infrastructure, such as platform or infrastructure teams, and potentially vendor management for ZTE products, should address this critical Struts RCE vulnerability. The initial step involves identifying all ZXCDN instances, assessing their business criticality and network exposure, and confirming ownership to plan a risk-based remediation strategy.

  • ZXCDN platform owners should address.
  • Verify ZXCDN instances and exposure.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZTE ZXCDN?

ZTE ZXCDN is a Content Delivery Network product used to manage, optimize, and accelerate the distribution of digital content across networks. By acting as an edge infrastructure component, it sits between users and data to efficiently handle large volumes of traffic, which is why it is often positioned at the perimeter of an organization's network.

What does the Struts vulnerability mean for CVE-2025-46581?

This CVE involves a vulnerability classified as CWE-94, which refers to improper control of generation of code. In simple terms, the software incorrectly processes certain inputs, allowing an unauthorized person to inject and run their own commands directly on the server. This bypasses typical security controls, granting them the ability to execute unauthorized instructions.

How does an attacker trigger CVE-2025-46581?

An attacker triggers this vulnerability by sending specially crafted network requests to the system. Importantly, the flaw does not require the attacker to have a valid user account or any prior special access to the device. However, requests that do not adhere to the specific structure required to exploit the underlying Struts framework will not successfully execute commands.

Do I need to worry about this if my ZXCDN instance is internal?

Halo Surface Signal notes that ZXCDN is typically designed for edge deployments to manage external traffic, making internet-facing configurations common. While devices exposed directly to the internet face the highest risk, any system reachable by an attacker over a network is potentially at risk. You should evaluate if your specific instance is accessible to untrusted network segments.

When should I take action for CVE-2025-46581?

Because this is a critical remote code execution flaw, you should prioritize identifying all instances of ZXCDN within your infrastructure immediately. Once identified, assess their network reachability and business role. Coordinate with your vendor management or infrastructure teams to review official support channels for guidance on remediation steps.

References