Impact
The Z80Ultra (NX741J) product allows any local application that is not privileged to retrieve the Wi‑Fi MAC address by reading the factory_mac_address field in the Settings.Secure database. This leak exposes a unique device identifier that can be used for tracking or fingerprinting, representing an information disclosure vulnerability.
Affected Systems
Affected devices are ZTE Z80Ultra models, specifically the NX741J product. The vulnerability exists in the factory firmware that permits read access to the factory_mac_address database field. No specific firmware versions are listed as affected, so caution should be applied to all current NX741J units.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity. EPSS is not available and the issue is not listed in KEV. Likely attack vector is local; any non‑privileged application on the device can query the read‑only database field. Once a legitimate app reads the MAC address the attacker receives the identifier; no further escalation is required.
OpenCVE Enrichment