CVE-2026-108503 PUBLISHED

Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product

Assigner: zte
Reserved: 10.10.2026 Published: 10.10.2026 Updated: 10.10.2026

ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 3.3

Product Status

Vendor ZTE
Product Z80 Ultra
Versions Default: unaffected
  • Version GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions is affected

Credits

  • EliGold finder

References

Problem Types

  • CWE-276 Incorrect default permissions CWE

Impacts

  • CAPEC-115 Authentication Bypass