CVE-2026-86551
Received Received - Intake

Wi-Fi MAC Address Exposure in Z80Ultra NX741J

Vulnerability report for CVE-2026-86551, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: ZTE Corporation

Description

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Z80Ultra (NX741J) product allows non-privileged programs to access the Wi-Fi MAC address by reading the factory_mac_address field in the Settings.Secure database. The MAC address is a unique identifier for network interfaces.

Detection Guidance

This vulnerability can be detected by checking if non-privileged programs can access the factory_mac_address field in the Settings.Secure database on devices running Z80Ultra (NX741J). No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to obtain the device's Wi-Fi MAC address without special permissions. While not directly causing data loss, this could aid in tracking or further network-based attacks if combined with other vulnerabilities.

Mitigation Strategies

Immediate mitigation steps include restricting access to the Settings.Secure database to prevent unauthorized retrieval of the Wi-Fi MAC address. Ensure only privileged applications can query the factory_mac_address field.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86551. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart