Executive brief
ZTE's monitoring module is a software component used to oversee and manage critical power system infrastructure. Attackers can exploit command injection vulnerabilities to delete essential system files, crash the monitoring service, steal sensitive credentials (such as SNMP passwords), and gain root-level access to tamper with power system configuration—potentially causing widespread operational failures and service outages.
Technical details
This vulnerability is a command injection flaw in ZTE's monitoring module that allows unauthenticated or low-privileged attackers to execute arbitrary OS commands. By injecting malicious commands, an attacker can delete critical runtime files, causing the monitoring service to crash. Additionally, the attacker can escalate privileges to root and extract sensitive configuration data including SNMP credentials. The attack is network-accessible and does not require user interaction. Successful exploitation results in loss of visibility into the power system, credential theft, and unauthorized modification of critical parameters.
Affected products
- ZTE Monitoring Module
Timeline
- 2026-08-31: disclosed