Junglewise Threat Intelligence

CVE-2026-44410: ZTE business logic flaw in cryptographic implementation

CVE-2026-44410 · Severity: low · CVSS 3.8 · Published 2026-05-26

Vendors: Zte.

Executive brief

A business logic vulnerability has been identified in a ZTE product. This flaw allows an attacker with high-level administrative privileges to use legitimate system functions in unintended ways. While the impact is limited, it could allow an authorized user to cause minor disruptions to service availability or data integrity beyond their intended scope of duties.

Technical details

This vulnerability is characterized as a business logic flaw (CWE-1240) within a ZTE application. The root cause involves the use of a cryptographic primitive with a risky implementation or a general failure to restrict legitimate functions to their intended operational flow. An attacker with high privileges (PR:H) can reach the vulnerable component over the network without user interaction. By deviating from the designer's expected workflow, the attacker can achieve a low impact on both integrity and availability. The specific product name was not disclosed in the primary advisory, but the vulnerability was reported by ZTE Corporation.

Affected products

  • ZTE Unknown Product

Timeline

  • 2026-05-26: disclosed: Initial disclosure by ZTE and NVD publication.

References