Description
ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.
Published: 2026-10-10
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to system interfaces
Action: Assess
AI Analysis

Impact

The vulnerability involves inadequate authentication for system interfaces, allowing third‑party applications to invoke protected functions through reflection and read sensitive information. This results in unauthorized data disclosure and is classified as a Weak Authentication and Authorization flaw (CWE‑269).

Affected Systems

ZTE Z80 Ultra devices are affected. No specific firmware or hardware revisions were listed in the advisory, so all released versions may be vulnerable unless otherwise updated by the vendor.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. With no EPSS data and no listing in the CISA KEV catalog, exploitation is considered low to moderate risk, but the lack of robust authentication could be leveraged by an attacker who gains network or local access to the device. The vulnerability can be exploited by invoking the exposed interfaces via reflection, which typically requires administrative privileges or permissions granted to installed third‑party apps. The precise attack vector is not explicitly stated, so this assessment is inferred from the description.

Generated by OpenCVE AI on October 10, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware from ZTE that explicitly addresses the authentication weakness.
  • Limit access to system interfaces by enforcing network segmentation and firewall rules so that only trusted hosts can reach the device.
  • Disable or restrict any unused management or debugging interfaces that are exposed to external clients.

Generated by OpenCVE AI on October 10, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.
Title Unauthorized access vulnerability in ZTE Z80 Ultra product
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-10-10T09:08:04.151Z

Reserved: 2026-10-10T03:20:37.908Z

Link: CVE-2026-108506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T10:16:44.087

Modified: 2026-10-10T10:16:44.087

Link: CVE-2026-108506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:30:10Z

Weaknesses
  • CWE-269

    Improper Privilege Management