Description
ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.
Published: 2026-10-10
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

ZTE Z80 Ultra contains a flaw where its system functions do not apply proper access checks, allowing the reading of sensitive data by an attacker. The vulnerability is classified as an access control failure, which could expose confidential information that the device holds or manages. The documented impact is limited to confidentiality loss; it does not affect integrity or availability.

Affected Systems

The Z80 Ultra product from ZTE is vulnerable. No specific version numbers are listed, so all current releases should be considered at risk until confirmed otherwise.

Risk and Exploitability

The CVSS v3.1 score of 3.3 indicates a low severity vulnerability. The EPSS score is not provided, and the flaw is not listed in the CISA KEV catalog at this time. Based on the description, the likely attack vector is remote, where an attacker can invoke exposed functions over the network if the management interface is reachable. Exploitation requires the attacker to access the interface and could be mitigated by blocking or restricting that access. Overall risk to a protected environment remains low, but the confidentiality breach could be valuable to adversaries.

Generated by OpenCVE AI on October 10, 2026 at 08:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an official firmware or firmware patch from ZTE that addresses the permission validation flaw in the Z80 Ultra.
  • Configure network devices or firewalls to restrict access to the Z80 Ultra’s management interfaces to trusted IP addresses or subnet ranges.
  • Disable or block any unused services or APIs that expose the vulnerable callable functions to reduce the attack surface.

Generated by OpenCVE AI on October 10, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.
Title Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-10-10T06:52:58.624Z

Reserved: 2026-10-10T03:20:37.908Z

Link: CVE-2026-108503

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:41.110

Modified: 2026-10-10T07:16:41.110

Link: CVE-2026-108503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions