Description
The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.
Published: 2026-09-20
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure: Wi‑Fi MAC address
Action: Assess Impact
AI Analysis

Impact

The Z80Ultra (NX741J) product allows any local application that is not privileged to retrieve the Wi‑Fi MAC address by reading the factory_mac_address field in the Settings.Secure database. This leak exposes a unique device identifier that can be used for tracking or fingerprinting, representing an information disclosure vulnerability.

Affected Systems

Affected devices are ZTE Z80Ultra models, specifically the NX741J product. The vulnerability exists in the factory firmware that permits read access to the factory_mac_address database field. No specific firmware versions are listed as affected, so caution should be applied to all current NX741J units.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity. EPSS is not available and the issue is not listed in KEV. Likely attack vector is local; any non‑privileged application on the device can query the read‑only database field. Once a legitimate app reads the MAC address the attacker receives the identifier; no further escalation is required.

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from ZTE that removes the exposed read‑only factory_mac_address field or otherwise restricts its visibility.
  • Configure application permissions or use access control lists to prevent non‑privileged programs from querying Settings.Secure, especially the factory_mac_address entry.
  • Monitor system logs for attempts to read the Settings.Secure factory_mac_address field and investigate any unexpected queries.

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte nx741j
Vendors & Products Zte
Zte nx741j

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.
Title Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) product
Weaknesses CWE-668
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-09-21T18:11:15.078Z

Reserved: 2026-09-08T02:55:56.712Z

Link: CVE-2026-86551

cve-icon Vulnrichment

Updated: 2026-09-21T18:11:10.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T02:16:51.310

Modified: 2026-09-22T19:41:38.447

Link: CVE-2026-86551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:00Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere