{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108503", "assignerOrgId": "6786b568-6808-4982-b61f-398b0d9679eb", "state": "PUBLISHED", "assignerShortName": "zte", "dateReserved": "2026-10-10T03:20:37.908Z", "datePublished": "2026-10-10T06:52:58.624Z", "dateUpdated": "2026-10-10T06:52:58.624Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "6786b568-6808-4982-b61f-398b0d9679eb", "shortName": "zte", "dateUpdated": "2026-10-10T06:52:58.624Z" }, "title": "Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-276", "description": "CWE-276 Incorrect default permissions", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-115", "descriptions": [ { "lang": "en", "value": "CAPEC-115 Authentication Bypass" } ] } ], "affected": [ { "vendor": "ZTE", "product": "Z80 Ultra", "versions": [ { "status": "affected", "version": "GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.
" } ] } ], "references": [ { "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/7927166620923281226" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseSeverity": "LOW", "baseScore": 3.3, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } } ], "credits": [ { "lang": "en", "value": "EliGold", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.5" } } } }