CVE-2026-108505: Information disclosure vulnerability in ZTE Z80 Ultra product
Published Oct 10, 2026
·Updated
ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.
Affected Software
1 affected component
ZTE Z80 Ultra
Event History
Oct 10, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A third-party application running on a ZTE Z80 Ultra can capture data returned by system interfaces. The provided information does not indicate that remote access or prior privileges are required.
2
Does exploitation require user interaction?
Yes. The CVSS vector indicates user interaction is required, so a user must take an action before the information disclosure can occur.
3
What information could be exposed?
The issue allows access to device-related information returned by system interfaces. The provided details do not identify the specific data fields exposed.