Executive brief
An information disclosure vulnerability exists in the ZTE MU5250, a portable 5G Wi-Fi hotspot device. Due to a flaw in how the device manages access permissions, an unauthorized user on the same local network could gain access to sensitive information. This could lead to the exposure of private device data or configuration details.
Technical details
An information disclosure vulnerability (CWE-200) exists in the ZTE MU5250 portable router. The root cause is an improper configuration of the access control mechanism, which fails to correctly restrict data access to authorized users. An attacker positioned on the adjacent network (e.g., connected to the same Wi-Fi or local network) with low-level privileges can exploit this flaw to retrieve sensitive information without proper authorization. The CVSS vector (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) indicates that while the attack requires local proximity and some level of authentication, it results in a high impact on confidentiality. Users are advised to check for firmware updates from ZTE.
Affected products
- ZTE MU5250
Timeline
- 2026-05-22: disclosed: Initial disclosure by ZTE Corporation
- 2026-05-22: advisory: NVD record published