CVE-2026-86551Low· 3.3▾ SunlitThe Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86555Medium· 6.2The ZTE SmartLife application has a hardcoded key
CVE-2026-86554Medium· 4.3SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process
CVE-2026-86553High· 8.8SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process
CVE-2026-86552Medium· 5.4SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime
CVE-2026-86550Medium· 6.5NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects
CVE-2022-38474Medium· 4.3A website that had permission to access the microphone could record audio without the audio notification being shown