-Infinity
0
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.

First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.

First published (updated )
Severity
5.7
AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.

First published (updated )
Severity
9.8
Code Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

First published (updated )
Severity
7.7
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user can bypass authorization checks to view the device's communication private key, resulting in key exposure and impacting communication security.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factorymacaddress in the Settings.Secure database.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

First published (updated )
Severity
6.2
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

First published (updated )

Technical write-up for four vulnerabilities I reported in ZTE SmartLife.

The main issue is CVE-2026-86553, a password reset flaw in the SmartLife account backend. The reset endpoint accepted the target accountId and a new password without requiring a reset code, old password, or validated reset transaction.

Another endpoint exposed whether an email was registered and returned the corresponding backend account ID. Using researcher-controlled accounts, the chain was:

email -> accountId -> password reset -> login with the new password

I verified the state change by confirming that the previous password stopped working and the newly selected password successfully returned a valid session.

The research also covered the app authentication mechanism used by the Android client, email ownership verification during registration, and the wider SmartLife/Homecare SDK surface available after login.

ZTE patched the reported issues and assigned CVE-2026-86552, CVE-2026-86553, CVE-2026-86554 and CVE-2026-86555.

First published (updated )
Social
reddit
Severity
6.5
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

NuBrowser lacks protocol whitelist validation for the S.browserfallbackurl field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.

First published (updated )
Severity
3.9
SQL Injection
AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

First published (updated )
Severity
1.8
Path Traversal
AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/rootpath), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.

First published (updated )
Severity
6.3
Infoleak
AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface.

First published (updated )
Severity
5.7
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user cookies, hijack session privileges, and tamper with page content.Since the malicious code is stored within the system, the attack scope is broad and the concealment is strong, making it frequently employed for data theft attacks.

First published (updated )
Severity
7
Weak Encryption
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

First published (updated )
Severity
3.8
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

First published (updated )
Severity
7.5
Infoleak
AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

First published (updated )
Severity
8.8
AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties.

First published (updated )
Severity
4.2
EPSS
0.01%
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.

First published (updated )
Severity
5.3
EPSS
0.04%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

First published (updated )
Severity
5.4
EPSS
0.03%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

First published (updated )
Severity
7.5
EPSS
0.04%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

First published (updated )
Severity
6.4
EPSS
0.03%
AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

First published (updated )
Severity
7.5
EPSS
0.12%
Input Validation
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203