CVE-2026-108506: ZTE z80 Ultra

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.

Affected products

Published 2026-10-10. Last modified 2026-10-10.