CVE-2023-25647: ZTE Axon 30 Firmware

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

Affected products

  • ZTE Axon 30 Firmware: before 3.0.0b06 (fixed in 3.0.0b06)
  • ZTE Axon 40 Pro Firmware: before 1.0.0b16 (fixed in 1.0.0b16)
  • ZTE Axon 40 Ultra Firmware: before 2.0.0b17 (fixed in 2.0.0b17)
  • ZTE Nubia z50 Firmware: before 1.0.0b19mr (fixed in 1.0.0b19mr)

Published 2023-08-17. Last modified 2026-06-17.