CVE-2026-108506 PUBLISHED

Unauthorized access vulnerability in ZTE Z80 Ultra product

Assigner: zte
Reserved: 10.10.2026 Published: 10.10.2026 Updated: 10.10.2026

ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 5.5

Product Status

Vendor ZTE
Product Z80 Ultra
Versions Default: unaffected
  • Version GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions is affected

Credits

  • EliGold finder

References

Problem Types

  • # CWE-269 Improper Privilege Management CWE

Impacts

  • CAPEC-115 Authentication Bypass