CVE-2026-49003
Deferred
Deferred - Pending Action
BaseFortify
Vulnerability report for CVE-2026-49003, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-31
Last updated on: 2026-09-01
Assigner: ZTE Corporation
Description
Description
Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ZTE | ZXDU68 | S202 V5.0 ZXDU68 S202 V5.0R02M02 ACB V1.30.01.00 γZXDU68 S202 V5.0R02M02 ACB V1.30.01.01γZXDU68 S202 V5.0R02M02 ACB V1.30.01.02γZXDU68 S202 V5.0R02M02 ACB V1.30.01.03 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |