CVE-2026-108503
Received
Received - Intake
ZTE Z80 Ultra Interface Permission Validation Flaw
Vulnerability report for CVE-2026-108503, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-10
Last updated on: 2026-10-10
Assigner: ZTE Corporation
Description
Description
ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ZTE | Z80 | Ultra GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |