CVE-2026-108504
MEDIUMCVSS 5.5/10EPSS 0.12%
Last modified
CVE-2026-108504 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ZTE | Z80 Ultra | GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-108504?
ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information.
How severe is CVE-2026-108504?
CVE-2026-108504 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2026-108504?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10849The hawkBit device management client in subsys/mgmt/hawkbit …7.5
- CVE-2026-1085The True Ranker plugin for WordPress is vulnerable to Cross-…4.3
- CVE-2026-10850Plane CE 1.3.1 allows a low-privileged project member to sub…5.4
- CVE-2026-108501ZTE Z80 Ultra has a system interface permission verification…5.7
- CVE-2026-108502ZTE Z80 Ultra contains an information disclosure vulnerabili…3.3
- CVE-2026-108503ZTE Z80 Ultra has an interface permission validation vulnera…3.3
- CVE-2026-108505ZTE Z80 Ultra has a local information disclosure vulnerabili…3.3
- CVE-2026-108506ZTE Z80 Ultra's system interfaces do not have robust invocat…5.5
- CVE-2026-10852IBM WebSphere Application Server and IBM WebSphere Applicati…7.5
- CVE-2026-108521A vulnerability has been found in Studio-Saelix Sencho up to…4.7
- CVE-2026-108522A vulnerability was found in Studio-Saelix Sencho up to 0.94…8.3
- CVE-2026-108523A vulnerability was determined in Studio-Saelix Sencho up to…4.3
Are you affected by CVE-2026-108504?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
