Impact
ZTE Z80 Ultra contains an unauthorized information disclosure vulnerability caused by insufficient access control for framework methods. The flaw allows an attacker to read device‑related information, compromising the confidentiality of the device. The weakness is identified as CWE‑269 (Insufficient Access Control).
Affected Systems
The affected product is ZTE Z80 Ultra. No specific software version details are provided in the CVE data.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate potential impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires access to the framework methods, likely through network exposure or local access; the exact attack vector is not explicitly stated in the advisory.
OpenCVE Enrichment