Executive brief
A security flaw in certain ZTE products allows unauthorized users to bypass security checks. This means an attacker could access sensitive system data or change critical configuration settings without needing a password. Such an exploit could lead to the exposure of private information or the disruption of system operations.
Technical details
The vulnerability is classified as Improper Access Control (CWE-284) within ZTE software. It stems from a failure to effectively validate user permissions, allowing unauthenticated attackers to interact with sensitive system components over the network. An attacker can exploit this to view or modify system configuration data, potentially leading to full system compromise or data exfiltration. The CVSS 3.1 score of 9.1 reflects high impact on confidentiality and integrity with no user interaction or privileges required.
Affected products
- ZTE ZTE Products
Timeline
- 2026-05-27: disclosed: Initial disclosure by ZTE Corporation
- 2026-05-27: advisory: NVD publication date