CVE-2026-49003
Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product
CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th
Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.
| CWE | CWE-287 |
| Vendor | zte |
| Product | zxdu68 s202 v5.0 |
| Published | Aug 31, 2026 |
| Last Updated | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for zte zxdu68 s202 v5.0
Be the first to know when new critical vulnerabilities affecting zte zxdu68 s202 v5.0 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
ZTE / ZXDU68 S202 V5.0
ZXDU68 S202 V5.0R02M02 ACB V1.30.01.00 、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.01、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.02、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.03
References
Credits
Muhammad Dio Pratama