CVE-2026-44410: Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE
Published May 26, 2026
·Updated
This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.
Affected Software
1 affected component
ZTE ZXUniPOS NDS-LTE
Event History
May 26, 2026
CVE Published
via MITRE·09:39 AM
Data Sourced
via MITRE·09:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44410?
The severity of CVE-2026-44410 is low, with a score of 3.8.
2
What is the risk associated with CVE-2026-44410?
CVE-2026-44410 has a risk rating of 26.
3
How do I fix CVE-2026-44410?
To address CVE-2026-44410, ensure that application functions are only utilized in intended ways and review business logic for vulnerabilities.
4
What type of vulnerability is CVE-2026-44410?
CVE-2026-44410 is a business logic flaw that allows exploitation of legitimate application functions.
5
Which software is affected by CVE-2026-44410?
CVE-2026-44410 affects ZTE ZXUniPOS NDS-LTE software.