# CVE-2024-22064

## Summary

- **CVE ID:** CVE-2024-22064
- **Severity:** HIGH
- **CVSS Score:** 8.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
- **CWE:** CWE-1051
- **Published:** May 10, 2024
- **Last Modified:** Mar 13, 2026

## Description

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.

## Affected Products

- ZTE — ZXUN-ePDG (V5.20.15)

## References

- [CNA](https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035524)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.46%
- **EPSS Percentile:** 38.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._