CVE-2026-86551 PUBLISHED

Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) product

Assigner: zte
Reserved: 08.09.2026 Published: 20.09.2026 Updated: 20.09.2026

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 3.3

Product Status

Vendor ZTE
Product NX741J
Versions Default: unaffected
  • Version GEN_ZTE_PQ85A01V1.0.0B23MR3 and all prior released versions is affected

Credits

  • EliGold finder

References

Problem Types

  • CWE-668 Exposure of Resource to Wrong Sphere CWE

Impacts

  • CAPEC-577 Owner Footprinting