Privacy Vulnerability in Z80Ultra Products by ZTE
CVE-2026-86551

3.3LOW

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-86551?

The Z80Ultra (NX741J) product is affected by a vulnerability that permits non-privileged programs to access sensitive information. Specifically, an attack can exploit this flaw to retrieve the Wi-Fi MAC address through a read-only field within the Settings.Secure database. This could potentially lead to privacy concerns as unauthorized entities gain insights into network identifiers.

Affected Version(s)

NX741J GEN_ZTE_PQ85A01V1.0.0B23MR3 and all prior released versions

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EliGold
.