Junglewise Threat Intelligence

CVE-2026-49001: ZTE Products Cross-Site Request Forgery

CVE-2026-49001 · Severity: medium · CVSS 5.3 · Published 2026-05-27

Vendors: Zte.

Executive brief

A security vulnerability has been identified in certain ZTE products that could allow an attacker to trick an authenticated administrator into performing unintended actions. By exploiting a user's active session, an attacker could potentially modify system configurations or tamper with data. This could lead to unauthorized changes in how the device operates or impact the integrity of the system's settings.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in certain ZTE products due to insufficient validation of cross-site requests. An attacker can exploit this by inducing an authenticated user with high privileges to visit a malicious website or click a crafted link while their session is active. Successful exploitation allows the attacker to forge requests that the application treats as legitimate, potentially leading to unauthorized configuration changes or data tampering. The attack requires high privileges (PR:H), user interaction (UI:R), and high complexity (AC:H) according to the provided CVSS vector. Users are advised to refer to ZTE's official support bulletins for specific product patches and mitigation steps.

Affected products

  • ZTE ZTE Products

Timeline

  • 2026-05-27: disclosed: Initial publication of the CVE record by ZTE Corporation.
  • 2026-05-27: advisory: ZTE published a security bulletin regarding the CSRF vulnerability.

References