PostgreSQL Service Misconfiguration and Command Injection in Mobile Devices by ZTE
CVE-2026-49004
6.5MEDIUM
What is CVE-2026-49004?
The built-in PostgreSQL service on ZTE mobile devices is affected by misconfiguration weaknesses and command injection vulnerabilities. This service operates on a specific port with root privileges, safeguarded by weak credentials. The presence of the COPY FROM PROGRAM syntax allows local attackers to circumvent Android’s permission sandbox, effectively granting them unauthorized full root access to the device.
Affected Version(s)
NX799J (Red Magic 11 Air) GEN_CN_NX799JV1.0.0B15
