Impact
ZTE Z80 Ultra routers contain a flaw that allows third‑party applications to read sensitive data by hooking system APIs. The vulnerability enables an attacker who can run or influence such applications to access information that is not intended for public or external use, compromising confidentiality. The weakness corresponds to improper authorization (CWE‑269) and does not, from the description, affect integrity or availability.
Affected Systems
Affected devices are ZTE Z80 Ultra routers. No specific firmware or hardware revisions are listed, so all current versions of this product family are potentially impacted until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 3.3 indicates a low overall severity, and the EPSS score is unavailable. The vulnerability is not yet in the CISA KEV catalog. Attackers would likely have to install or otherwise control a third‑party application on the device; the description implies a local or privileged escalation path rather than a remote code execution vector. With the current score and lack of widespread exploitation data, the risk is modest but non‑negligible for protecting confidential data.
OpenCVE Enrichment