There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1028664