Script Injection Vulnerability in ZTE Products
CVE-2026-48999

5.3MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48999?

This vulnerability allows attackers to inject malicious scripts, such as JavaScript, into vulnerable ZTE systems. When other users access affected pages, these scripts execute in their browsers, enabling attackers to steal sensitive data like cookies, hijack user sessions, and manipulate webpage content. The embedded nature of the malicious code provides significant concealment and increases the potential scale of attacks, making it a prevalent threat for data breaches.

Affected Version(s)

ZTE ZXUniPOS NDS-LTE V24.30.40CP02 and earlier versions

ZTE ZXUniPOS NDS-LTE V24.40.40 and earlier versions

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Venom Nguyen
.