Access Control Flaw in ZTE Z80 Ultra Smart Device
CVE-2026-108503

3.3LOW

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108503?

The ZTE Z80 Ultra exhibits a serious interface permission validation vulnerability where callable functions fail to enforce proper access controls. This deficiency allows unauthorized attackers to exploit the system, potentially accessing sensitive information and compromising device security. It is crucial for users to review their security practices and apply necessary updates or patches provided by ZTE to mitigate this risk.

Affected Version(s)

Z80 Ultra GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EliGold
.