---
id: CVE-2026-108503
title: ZTE Z80 Ultra has an interface permission validation vulnerability
summary: >-
  ZTE Z80 Ultra has an interface permission validation vulnerability. The
  callable functions provided by the system lack sufficient access control. An
  attacker can leverage these functions to read relevant information.
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-276
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T07:16:41.110'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108503'
references:
  - url: >-
      https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/7927166620923281226
    label: psirt@zte.com.cn
tags:
  - nvd
ingestedAt: '2026-10-10T07:26:21.923Z'
---

## Overview

ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
