Script Injection Vulnerability in ZTE Products
CVE-2026-48999

5.7MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48999?

This vulnerability allows attackers to inject malicious scripts, such as JavaScript, into vulnerable ZTE systems. When other users access affected pages, these scripts execute in their browsers, enabling attackers to steal sensitive data like cookies, hijack user sessions, and manipulate webpage content. The embedded nature of the malicious code provides significant concealment and increases the potential scale of attacks, making it a prevalent threat for data breaches.

Affected Version(s)

ZXUniPOS NDS-LTE Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01)

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Venom Nguyen
.