CVE-2026-49004
PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
| CWE | CWE-89 |
| Vendor | zte |
| Product | nx799j (red magic 11 air) |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for zte nx799j (red magic 11 air)
Be the first to know when new medium vulnerabilities affecting zte nx799j (red magic 11 air) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L Attack Vector
Physical
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low
Affected Versions
ZTE / NX799J (Red Magic 11 Air)
GEN_CN_NX799JV1.0.0B15
References
Credits
Littlenine and Sunflowe