CVE-2026-49003: Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product

Published Aug 31, 2026
·
Updated

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.

Affected Software

1 affected component
ZTE ZXDU68 S202=V5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Isolate the affected ZTE ZXDU68 S202 V5.0 Product from untrusted networks until a vendor patch is applied, to prevent unauthenticated RCE/command injection exploitation.

  2. Operational

    If configuration passwords (e.g., SNMP) may have been stolen via the root-privilege compromise, rotate those credentials immediately before resuming normal operations.

Event History

Aug 31, 2026
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The vulnerability is rated with no privileges required and no user interaction required. It is attackable over an adjacent network, so the attacker must be able to reach the affected device from a neighboring network segment.

2

What could an attacker do after successful exploitation?

An attacker could execute commands to delete core runtime files and crash the monitoring module. They could also obtain root privileges, steal configuration passwords such as SNMP credentials, alter critical system parameters, and disrupt power-system operation.

3

How can I determine whether my device is affected?

The affected software identified in the available data is ZTE ZXDU68 S202 V5.0. Review deployed ZXDU68 S202 devices and confirm whether they run that version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203