Impact
ZTE Z80 Ultra contains a flaw where its system functions do not apply proper access checks, allowing the reading of sensitive data by an attacker. The vulnerability is classified as an access control failure, which could expose confidential information that the device holds or manages. The documented impact is limited to confidentiality loss; it does not affect integrity or availability.
Affected Systems
The Z80 Ultra product from ZTE is vulnerable. No specific version numbers are listed, so all current releases should be considered at risk until confirmed otherwise.
Risk and Exploitability
The CVSS v3.1 score of 3.3 indicates a low severity vulnerability. The EPSS score is not provided, and the flaw is not listed in the CISA KEV catalog at this time. Based on the description, the likely attack vector is remote, where an attacker can invoke exposed functions over the network if the management interface is reachable. Exploitation requires the attacker to access the interface and could be mitigated by blocking or restricting that access. Overall risk to a protected environment remains low, but the confidentiality breach could be valuable to adversaries.
OpenCVE Enrichment