CVE-2026-49002 PUBLISHED

Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product

Assigner: zte
Reserved: 27.05.2026 Published: 27.05.2026 Updated: 27.05.2026

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor ZTE
Product ZXUniPOS NDS-LTE
Versions Default: unaffected
  • Version V24.30.40CP02 and earlier versions is affected
  • Version V24.40.40 and earlier versions is affected

Credits

  • Venom Nguyen finder

References

Problem Types

  • CWE-284: Improper Access Control CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs