Description
ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.
Published: 2026-10-10
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

ZTE Z80 Ultra routers contain a flaw that allows third‑party applications to read sensitive data by hooking system APIs. The vulnerability enables an attacker who can run or influence such applications to access information that is not intended for public or external use, compromising confidentiality. The weakness corresponds to improper authorization (CWE‑269) and does not, from the description, affect integrity or availability.

Affected Systems

Affected devices are ZTE Z80 Ultra routers. No specific firmware or hardware revisions are listed, so all current versions of this product family are potentially impacted until a vendor fix is applied.

Risk and Exploitability

The CVSS score of 3.3 indicates a low overall severity, and the EPSS score is unavailable. The vulnerability is not yet in the CISA KEV catalog. Attackers would likely have to install or otherwise control a third‑party application on the device; the description implies a local or privileged escalation path rather than a remote code execution vector. With the current score and lack of widespread exploitation data, the risk is modest but non‑negligible for protecting confidential data.

Generated by OpenCVE AI on October 10, 2026 at 08:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware patch released by ZTE for the Z80 Ultra product family via the vendor support portal
  • Limit the installation of third‑party applications or disable the system APIs that can be hooked, reducing the attack surface
  • Monitor device logs for unexpected API calls or unauthorized data reads to detect potential exploitation attempts

Generated by OpenCVE AI on October 10, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.
Title Information disclosure vulnerability in ZTE Z80 Ultra product
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-10-10T06:36:48.764Z

Reserved: 2026-10-10T03:20:37.908Z

Link: CVE-2026-108502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.980

Modified: 2026-10-10T07:16:40.980

Link: CVE-2026-108502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management