Junglewise Threat Intelligence

CVE-2026-49002: ZTE improper access control in system configuration

CVE-2026-49002 · Severity: critical · CVSS 9.1 · Published 2026-05-27

Vendors: Zte.

Executive brief

A security flaw in certain ZTE products allows unauthorized users to bypass security checks. This means an attacker could access sensitive system data or change critical configuration settings without needing a password. Such an exploit could lead to the exposure of private information or the disruption of system operations.

Technical details

The vulnerability is classified as Improper Access Control (CWE-284) within ZTE software. It stems from a failure to effectively validate user permissions, allowing unauthenticated attackers to interact with sensitive system components over the network. An attacker can exploit this to view or modify system configuration data, potentially leading to full system compromise or data exfiltration. The CVSS 3.1 score of 9.1 reflects high impact on confidentiality and integrity with no user interaction or privileges required.

Affected products

  • ZTE ZTE Products

Timeline

  • 2026-05-27: disclosed: Initial disclosure by ZTE Corporation
  • 2026-05-27: advisory: NVD publication date

References