CVE-2026-49003: Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product
Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Isolate the affected ZTE ZXDU68 S202 V5.0 Product from untrusted networks until a vendor patch is applied, to prevent unauthenticated RCE/command injection exploitation.
- Operational
If configuration passwords (e.g., SNMP) may have been stolen via the root-privilege compromise, rotate those credentials immediately before resuming normal operations.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is rated with no privileges required and no user interaction required. It is attackable over an adjacent network, so the attacker must be able to reach the affected device from a neighboring network segment.
What could an attacker do after successful exploitation?
An attacker could execute commands to delete core runtime files and crash the monitoring module. They could also obtain root privileges, steal configuration passwords such as SNMP credentials, alter critical system parameters, and disrupt power-system operation.
How can I determine whether my device is affected?
The affected software identified in the available data is ZTE ZXDU68 S202 V5.0. Review deployed ZXDU68 S202 devices and confirm whether they run that version.