CVE-2026-49002: Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49002?
The severity of CVE-2026-49002 is rated as critical with a score of 9.1.
What is CVE-2026-49002?
CVE-2026-49002 is a Broken Access Control vulnerability in ZTE ZXUniPOS NDS-LTE that allows unauthorized access to system data.
How do I fix CVE-2026-49002?
To fix CVE-2026-49002, apply the latest security updates and patches provided by ZTE for the ZXUniPOS NDS-LTE software.
What risks are associated with CVE-2026-49002?
The risks associated with CVE-2026-49002 include unauthorized access to sensitive configuration information and potential data integrity issues.
How does CVE-2026-49002 affect users?
CVE-2026-49002 can compromise user security by allowing unauthorized users to view and modify configuration data without proper permissions.