Impact
The vulnerability in the ZTE Z80 Ultra product arises from a missing access control check on a system interface. This flaw allows an attacker to invoke the interface reflectively and read sensitive information that should be protected. The associated weakness is a authority bypass, categorized as CWE-269, and the CVSS score indicates a moderate severity of 5.7. The impact is that authorized or unauthenticated users can potentially compromise confidentiality of the data exposed via the interface.
Affected Systems
The affected device is the ZTE Z80 Ultra. No specific firmware or software version is detailed in the advisory, so all installations of this product model should be considered potentially vulnerable until a vendor update is confirmed.
Risk and Exploitability
With a CVSS score of 5.7, the risk is moderate but non-negligible. The EPSS score is not reported, meaning the likelihood of exploitation is unclear, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the exposed system interface, which may be reachable over the network or locally, allowing an attacker or any user with interface access to retrieve data. An attacker does not need additional credentials beyond able to reach the interface, but the absence of further mitigation in the system configuration can enable passive data collection. The vulnerability requires no special conditions beyond interface access and can be exploited by an adversary who can send the appropriate request to the affected product.
OpenCVE Enrichment