Description
ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.
Published: 2026-10-10
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A local information disclosure flaw exists in ZTE Z80 Ultra that allows locally running third‑party applications to capture data returned by system interfaces. The exposed data contains device‑related information, which could reveal configuration details or identifiers. The weakness is a privilege management error (CWE‑269). This does not permit code execution or direct compromise, but the disclosure may assist adversaries in tailoring subsequent attacks or mapping network topologies.

Affected Systems

The Z80 Ultra product by ZTE is affected. No specific firmware or software versions are listed, so all devices of this model should be treated as potentially vulnerable.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity and the EPSS value is not available. The vulnerability is not listed in CISA’s KEV catalog. As the flaw requires local execution of a third‑party application that can read system‑interface data, the attack vector is likely local and constrained to devices with installed applications capable of interface access.

Generated by OpenCVE AI on October 10, 2026 at 10:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check with ZTE for a vendor‑supplied patch or firmware update that mitigates the local data capture issue.
  • Prevent installation of arbitrary third‑party applications that can access system interfaces, restricting local software to trusted sources only.
  • Deploy network segmentation to isolate the Z80 Ultra from untrusted or public networks, reducing exposure of system‑returned data.

Generated by OpenCVE AI on October 10, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.
Title Information disclosure vulnerability in ZTE Z80 Ultra product
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-10-10T08:50:06.263Z

Reserved: 2026-10-10T03:20:37.908Z

Link: CVE-2026-108505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T09:16:39.070

Modified: 2026-10-10T09:16:39.070

Link: CVE-2026-108505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:30:10Z

Weaknesses
  • CWE-269

    Improper Privilege Management