CVE-2026-108506: Unauthorized access vulnerability in ZTE Z80 Ultra product
ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Devices running the ZTE Z80 Ultra software are affected where third-party applications can execute on the device. The attack vector is local, so it is not described as remotely exploitable over the network.
What does an attacker need to exploit it?
An attacker needs to get a third-party application onto the device and have a user interact with it. No privileges are required, and the application can use reflection to invoke insufficiently protected system interfaces.
What is the likely impact of successful exploitation?
A malicious third-party application may retrieve information exposed through the affected system interfaces. The provided severity vector indicates high confidentiality impact, with no stated integrity or availability impact.