Sceawere
Vulnerability Detail
CVE-2026-108505UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ZTE Z80 Ultra Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.3
- Creation Date
- 3h ago
- Vendor
- ZTE
- Product
- Z80 Ultra
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.3",
"pubDate": "2026-10-10T09:16:39.070Z",
"pubdate": "2026-10-10T09:16:39.070Z",
"executiveSummary": "The ZTE Z80 Ultra is susceptible to a local information disclosure vulnerability originating from improper access control in system-level interfaces.\nThis vulnerability allows unauthorized third-party applications to intercept or query sensitive device metadata and internal system state information returned by the affected interfaces.\nThe vulnerability type is classified as Information Exposure, where the security boundary between the application sandbox and the system layer is circumvented.\nThe primary risk implication involves the compromise of device-specific telemetry and potentially sensitive internal identifiers that could be used for fingerprinting, target profiling, or as a component in more complex multi-stage exploit chains.\nExploitation requires the presence of a malicious or compromised third-party application on the device. As the attack vector is local, the attacker must have the ability to execute arbitrary code within the context of a standard user application, requiring no special system privileges to initiate the data harvesting process.\nThe impact is limited to unauthorized data access; however, the persistent nature of the information leakage poses a significant privacy and security risk for end-users.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient enforcement of permission-based access controls for specific system interfaces (APIs/Services) exposed by the ZTE Z80 Ultra firmware.\nIn the Android or Linux-based environment of the Z80 Ultra, system-level services typically export interfaces intended for authorized system processes. Due to a design flaw in the inter-process communication (IPC) implementation, these interfaces fail to validate the calling process's identity, security context, or declared manifest permissions before returning sensitive system data.\nAn attacker exploits this by crafting a malicious application that invokes these unprotected system interfaces. When the application performs a request, the system service processes the query and returns the sensitive data directly to the unprivileged process. This effectively bypasses the expected mediation layers that should restrict sensitive information to system-signed or privileged applications.\nThe attack flow follows a straightforward trajectory: 1) The attacker installs a seemingly benign application with no specific high-level permissions on the Z80 Ultra device. 2) The application initiates an IPC call (such as a Binder transaction or a direct socket/API call depending on the interface) to the vulnerable system component. 3) The vulnerable component, lacking a robust caller verification check, processes the request and responds with the requested system information. 4) The application captures this payload and transmits it to a remote command-and-control (C2) server or stores it locally for analysis.\nThe affected components are the system-layer services responsible for managing hardware identification, device state telemetry, and internal system configurations. Because these services are core to the device operation, they are active at all times, making the vulnerability persistently exploitable regardless of the current user session state.\nPost-exploitation, the impact involves the unauthorized collection of non-public device identifiers, which could be leveraged to de-anonymize the user or facilitate targeted attacks based on the specific device configuration detected. The lack of privilege requirements for the calling process makes this a low-barrier, high-impact privacy flaw."
}