Description
There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an information disclosure issue arising from improper permission control in the ZTE U30 Air. Attackers can exploit the flaw to retrieve relevant system information that should be protected. This can lead to a compromise of confidentiality, allowing an adversary to learn network topology, credentials, or configuration details that might aid further attacks. The weakness falls under the category of access control flaws (CWE‑269).

Affected Systems

This flaw affects the ZTE U30 Air product. No specific firmware versions are enumerated in the CNA data, so any release of the U30 Air that contains uncorrected permission handling is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level, and the EPSS score is not available, so it is not possible to gauge the current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need some network or local access to the device, leveraging the deficient permission checks, to gain the disclosed information. The impact is limited to the data exposed but could provide a foothold for other attacks.

Generated by OpenCVE AI on September 30, 2026 at 07:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the ZTE U30 Air firmware update released by the vendor to correct the permission control issue.
  • Restrict network access to the device’s management interface to trusted IP ranges and enforce strong authentication.
  • Configure logging and routinely review access logs for anomalous activity.

Generated by OpenCVE AI on September 30, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.
Title An information disclosure vulnerability in ZTE U30 Air product
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-09-30T14:37:59.494Z

Reserved: 2026-09-08T02:55:56.712Z

Link: CVE-2026-86556

cve-icon Vulnrichment

Updated: 2026-09-30T14:37:55.888Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T03:17:00.237

Modified: 2026-09-30T16:29:22.650

Link: CVE-2026-86556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management