Impact
The vulnerability involves inadequate authentication for system interfaces, allowing third‑party applications to invoke protected functions through reflection and read sensitive information. This results in unauthorized data disclosure and is classified as a Weak Authentication and Authorization flaw (CWE‑269).
Affected Systems
ZTE Z80 Ultra devices are affected. No specific firmware or hardware revisions were listed in the advisory, so all released versions may be vulnerable unless otherwise updated by the vendor.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. With no EPSS data and no listing in the CISA KEV catalog, exploitation is considered low to moderate risk, but the lack of robust authentication could be leveraged by an attacker who gains network or local access to the device. The vulnerability can be exploited by invoking the exposed interfaces via reflection, which typically requires administrative privileges or permissions granted to installed third‑party apps. The precise attack vector is not explicitly stated, so this assessment is inferred from the description.
OpenCVE Enrichment