CVE-2026-86551

Summary

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

Affected Software

VendorProductVersion RangeStatus
ZTENX741JGEN_ZTE_PQ85A01V1.0.0B23MR3 and all prior released versionsaffected

Weaknesses

  • CWE-668: CWE-668 Exposure of Resource to Wrong Sphere

References