CVE-2026-86556
Received Received - Intake

Information Disclosure in ZTE U30 Air

Vulnerability report for CVE-2026-86556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: ZTE Corporation

Description

There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zte u30_air *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in ZTE U30 Air. It occurs due to improper permission control, allowing attackers to access sensitive information without proper authorization.

Impact Analysis

Attackers could exploit this to obtain confidential data from the device, potentially leading to privacy breaches or unauthorized access to system information.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by enabling unauthorized access to personal or sensitive information, risking non-compliance.

Mitigation Strategies

Update the ZTE U30 Air firmware to the latest version provided by ZTE to address improper permission controls. Restrict network access to the device to trusted sources only. Monitor network traffic for unusual information requests targeting the device.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart