PostgreSQL Service Misconfiguration and Command Injection in Mobile Devices by ZTE
CVE-2026-49004

6.5MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
5 August 2026

What is CVE-2026-49004?

The built-in PostgreSQL service on ZTE mobile devices is affected by misconfiguration weaknesses and command injection vulnerabilities. This service operates on a specific port with root privileges, safeguarded by weak credentials. The presence of the COPY FROM PROGRAM syntax allows local attackers to circumvent Android’s permission sandbox, effectively granting them unauthorized full root access to the device.

Affected Version(s)

NX799J (Red Magic 11 Air) GEN_CN_NX799JV1.0.0B15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Littlenine and Sunflowe
.