Unauthorized Information Disclosure in ZTE Z80 Ultra
CVE-2026-108504

5.5MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108504?

The ZTE Z80 Ultra is vulnerable to unauthorized information disclosure due to inadequate access controls on certain methods within its framework. This weakness allows an attacker to exploit these methods, potentially enabling them to read sensitive device-related information. Users are advised to apply the latest security updates and review access control measures to mitigate the risk of exposure.

Affected Version(s)

Z80 Ultra GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EliGold
.