Sceawere
Vulnerability Detail
CVE-2026-108504UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ZTE Z80 Ultra Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 2h ago
- Vendor
- ZTE
- Product
- Z80 Ultra
- Attack Type
- # CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-10T08:17:04.510Z",
"pubdate": "2026-10-10T08:17:04.510Z",
"executiveSummary": "The ZTE Z80 Ultra contains an unauthorized information disclosure vulnerability stemming from insufficient access control mechanisms within its internal framework.\nThis vulnerability allows an unauthenticated or low-privileged attacker to bypass existing security restrictions and gain unauthorized access to sensitive device-related information.\nThe flaw resides in the improper implementation of authorization checks for specific methods exposed by the framework.\nSuccessful exploitation results in the exposure of internal system data, which could be leveraged to facilitate further attacks, support reconnaissance efforts, or reveal proprietary device configurations.\nThe impact is categorized as a significant information leakage issue, potentially compromising the confidentiality of the device's operational environment.\nThere are no specific mentions of complex exploitation requirements, suggesting the interface may be accessible via standard framework interaction methods.",
"technicalDetails": "The vulnerability is classified as an improper access control issue within the device's framework layer. The root cause is the failure to enforce robust authorization logic on specific framework-level methods responsible for retrieving system-level or device-specific telemetry and configuration metadata.\nIn the affected ZTE Z80 Ultra, certain internal methods are exposed without adequate validation of the calling context or the security context of the initiator. Typically, framework methods that provide diagnostic or hardware information should be gated by a permission model that mandates sufficient privilege levels (e.g., system-level or platform-signed identity). In this instance, the framework fails to perform these identity checks before executing the requested data retrieval routines.\nThe attack flow involves the interaction with these unprotected methods via the inter-process communication (IPC) mechanisms or exposed application programming interfaces (APIs) inherent to the device framework. An attacker can invoke these methods directly by targeting the specific exported components that wrap the vulnerable logic. Once the method is triggered, the framework proceeds to collect device-related information—such as hardware identifiers, peripheral status, or internal configuration flags—and returns this sensitive data to the requester without verifying if the requesting process has the authority to view such information.\nBecause the vulnerability exists at the framework level, it does not necessarily require the attacker to have high-level privileges; the barrier to entry is minimal provided the attacker can communicate with the vulnerable framework service. The information disclosed is specific to the ZTE Z80 Ultra, likely including data that aids in mapping the internal system architecture, which is a critical step for developing more sophisticated exploits.\nPost-exploitation, the disclosed information provides the attacker with a footprint of the device's internal state. This data can be utilized to craft targeted exploits for other components or to bypass additional security features by understanding specific internal naming conventions, memory layouts, or hardware configurations. The impact is significant in terms of confidentiality loss, as it subverts the principle of least privilege mandated for sensitive device operations."
}