CVE-2026-108503

low

Description

ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.

References

https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/7927166620923281226

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-96205

Details

Source: Mitre, NVD

Published: 2026-10-10

Updated: 2026-10-10

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00129