Executive brief
A vulnerability in a ZTE product allows attackers to inject malicious scripts into the system. When other users or administrators view the affected pages, these scripts execute automatically in their browsers. This can lead to the theft of login credentials, unauthorized session access, and the unauthorized modification of page content.
Technical details
This is a stored cross-site scripting (XSS) vulnerability (CWE-79) identified in a ZTE product. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to inject malicious JavaScript into the system. Exploitation requires high privileges (PR:H) and some user interaction (UI:R), such as a victim viewing a specific page. Once executed, the script can steal session cookies, hijack user privileges, or tamper with the integrity of the web interface. The vulnerability is tracked as CVE-2026-48999 and was reported by ZTE Corporation.
Affected products
- ZTE Unknown Product
Timeline
- 2026-05-27: advisory: Advisory published by ZTE and NVD.