Impact
The vulnerability is an information disclosure issue arising from improper permission control in the ZTE U30 Air. Attackers can exploit the flaw to retrieve relevant system information that should be protected. This can lead to a compromise of confidentiality, allowing an adversary to learn network topology, credentials, or configuration details that might aid further attacks. The weakness falls under the category of access control flaws (CWE‑269).
Affected Systems
This flaw affects the ZTE U30 Air product. No specific firmware versions are enumerated in the CNA data, so any release of the U30 Air that contains uncorrected permission handling is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level, and the EPSS score is not available, so it is not possible to gauge the current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need some network or local access to the device, leveraging the deficient permission checks, to gain the disclosed information. The impact is limited to the data exposed but could provide a foothold for other attacks.
OpenCVE Enrichment