Sceawere

Vulnerability Detail

CVE-2026-108505UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ZTE Z80 Ultra Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
3h ago
Vendor
ZTE
Product
Z80 Ultra
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-10T09:16:39.070Z",
  "pubdate": "2026-10-10T09:16:39.070Z",
  "executiveSummary": "The ZTE Z80 Ultra is susceptible to a local information disclosure vulnerability originating from improper access control in system-level interfaces.\nThis vulnerability allows unauthorized third-party applications to intercept or query sensitive device metadata and internal system state information returned by the affected interfaces.\nThe vulnerability type is classified as Information Exposure, where the security boundary between the application sandbox and the system layer is circumvented.\nThe primary risk implication involves the compromise of device-specific telemetry and potentially sensitive internal identifiers that could be used for fingerprinting, target profiling, or as a component in more complex multi-stage exploit chains.\nExploitation requires the presence of a malicious or compromised third-party application on the device. As the attack vector is local, the attacker must have the ability to execute arbitrary code within the context of a standard user application, requiring no special system privileges to initiate the data harvesting process.\nThe impact is limited to unauthorized data access; however, the persistent nature of the information leakage poses a significant privacy and security risk for end-users.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient enforcement of permission-based access controls for specific system interfaces (APIs/Services) exposed by the ZTE Z80 Ultra firmware.\nIn the Android or Linux-based environment of the Z80 Ultra, system-level services typically export interfaces intended for authorized system processes. Due to a design flaw in the inter-process communication (IPC) implementation, these interfaces fail to validate the calling process's identity, security context, or declared manifest permissions before returning sensitive system data.\nAn attacker exploits this by crafting a malicious application that invokes these unprotected system interfaces. When the application performs a request, the system service processes the query and returns the sensitive data directly to the unprivileged process. This effectively bypasses the expected mediation layers that should restrict sensitive information to system-signed or privileged applications.\nThe attack flow follows a straightforward trajectory: 1) The attacker installs a seemingly benign application with no specific high-level permissions on the Z80 Ultra device. 2) The application initiates an IPC call (such as a Binder transaction or a direct socket/API call depending on the interface) to the vulnerable system component. 3) The vulnerable component, lacking a robust caller verification check, processes the request and responds with the requested system information. 4) The application captures this payload and transmits it to a remote command-and-control (C2) server or stores it locally for analysis.\nThe affected components are the system-layer services responsible for managing hardware identification, device state telemetry, and internal system configurations. Because these services are core to the device operation, they are active at all times, making the vulnerability persistently exploitable regardless of the current user session state.\nPost-exploitation, the impact involves the unauthorized collection of non-public device identifiers, which could be leveraged to de-anonymize the user or facilitate targeted attacks based on the specific device configuration detected. The lack of privilege requirements for the calling process makes this a low-barrier, high-impact privacy flaw."
}
CVE-2026-108505: ZTE Z80 Ultra Information Disclosure (LOW Severity, CVSS: 3.3) | Sceawere