Sceawere
Vulnerability Detail
CVE-2026-86556UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ZTE U30 Air Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- ZTE
- Product
- U30 Air
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T03:17:00.237Z",
"pubdate": "2026-09-30T03:17:00.237Z",
"executiveSummary": "The ZTE U30 Air contains an information disclosure vulnerability stemming from improper permission control mechanisms.\nThis flaw allows unauthorized actors to bypass established access restrictions to retrieve sensitive data from the device.\nThe vulnerability affects the ZTE U30 Air product line and represents a significant security risk, as it permits attackers with network connectivity to obtain information that should be protected by authentication or authorization layers.\nThe impact includes the potential leakage of sensitive configuration data, system information, or internal credentials, which could facilitate further exploitation of the device.\nExploitation does not inherently require complex injection payloads but rather relies on the failure of the underlying access control logic to validate the privileges of the requesting entity.\nUsers and administrators should prioritize restrictive network configurations and monitor for unauthorized access attempts as primary defense strategies until specific vendor patches are verified.",
"technicalDetails": "The core of this vulnerability lies in an improper implementation of access control checks within the ZTE U30 Air software environment. By failing to enforce strict permission requirements on specific API endpoints or internal system services, the device exposes sensitive internal data to unauthorized requests.\nThe root cause is identified as an authorization bypass, where the application logic fails to perform adequate validation of the requester's identity or privilege level before processing requests for sensitive information. Consequently, requests that should be denied or redirected are processed by the service, returning the requested data to the attacker.\nThe attack flow typically involves an attacker sending crafted requests—often via HTTP/HTTPS or proprietary management protocols—directly to the vulnerable endpoint. Because the system lacks a robust authorization check, the request is handled as a legitimate interaction. The vulnerable component, likely a web-based management interface or an internal API service, retrieves the data from memory or the file system and transmits it back to the unauthenticated or unauthorized remote party.\nThis vulnerability is particularly concerning as it does not require prior knowledge of legitimate user credentials. The attack can be conducted over the network, making it a remote information disclosure vulnerability. If the management interface is exposed to the WAN or an untrusted segment of the local network, the risk profile increases significantly.\nThe post-exploitation impact includes the potential retrieval of system configuration files, environmental variables, or diagnostic logs. In many scenarios, this information is sufficient to map the device's internal structure, identify secondary vulnerabilities, or obtain credentials that lead to full administrative compromise. Since the vulnerability resides within the permission control logic, the scope of the exposure is determined by the specific data accessible to the service handler associated with the bypassed interface."
}