ZTE Z80 Ultra Interface Vulnerability Exposes Sensitive Information
CVE-2026-108501

5.7MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108501?

The ZTE Z80 Ultra is affected by a security flaw that compromises the integrity of system interface permissions. Due to the absence of essential access control measures, malicious actors can exploit this defect to read sensitive information by invoking the interface reflectively. This vulnerability highlights the need for robust access controls to prevent unauthorized data access and ensure the protection of sensitive information.

Affected Version(s)

ZTE Z80 Ultra GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EliGold
.