Command Injection Vulnerability in ZTE Communications Product
CVE-2026-49003

9.6CRITICAL

Key Information:

Vendor

Zte

Vendor
CVE Published:
31 August 2026

What is CVE-2026-49003?

A command injection vulnerability in ZTE's communications product allows attackers to execute unauthorized commands, potentially deleting critical system runtime files. This exploitation may lead to the failure of the monitoring module, granting the attacker root privileges to access sensitive information, including configuration passwords. With these elevated privileges, an attacker can alter vital system parameters, compromising the reliability and security of the entire power system.

Affected Version(s)

ZXDU68 S202 V5.0 ZXDU68 S202 V5.0R02M02 ACB V1.30.01.00 、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.01、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.02、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.03

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Dio Pratama
.