Impact
A local information disclosure flaw exists in ZTE Z80 Ultra that allows locally running third‑party applications to capture data returned by system interfaces. The exposed data contains device‑related information, which could reveal configuration details or identifiers. The weakness is a privilege management error (CWE‑269). This does not permit code execution or direct compromise, but the disclosure may assist adversaries in tailoring subsequent attacks or mapping network topologies.
Affected Systems
The Z80 Ultra product by ZTE is affected. No specific firmware or software versions are listed, so all devices of this model should be treated as potentially vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity and the EPSS value is not available. The vulnerability is not listed in CISA’s KEV catalog. As the flaw requires local execution of a third‑party application that can read system‑interface data, the attack vector is likely local and constrained to devices with installed applications capable of interface access.
OpenCVE Enrichment