Home

Description

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

PUBLISHED Reserved 2026-05-06 | Published 2026-05-22 | Updated 2026-05-22 | Assigner zte




MEDIUM: 5.7CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

BD_FLYMODEMMU5250V1.0.0B27
affected

Credits

Duc Anh Nguyen (from NTCS&TinyxLab) finder

References

support.zte.com.cn/...ui/bulletin/detail/3711746568357343342

cve.org (CVE-2026-44409)

nvd.nist.gov (CVE-2026-44409)

Download JSON