CVE-2026-49003
9.6ZTE · ZXDU68 S202 V5.0
A command injection vulnerability in the ZTE ZXDU68 S202 V5.0 allows unauthenticated attackers to gain root privileges, delete critical system files, and compromise power system configurations.
Executive summary
A critical command injection vulnerability in ZTE ZXDU68 S202 V5.0 power management units allows unauthenticated attackers to execute arbitrary code with root privileges, posing a severe risk to infrastructure.
Vulnerability
The device suffers from an improper authentication flaw leading to command injection. This allows an unauthenticated attacker to inject malicious commands, resulting in the deletion of system runtime files, denial of service, and full administrative control via root access.
Business impact
Successful exploitation of this vulnerability leads to a total compromise of the affected power management unit. Given the CVSS score of 9.6, the risk is extreme, as an attacker can disable monitoring modules and tamper with configuration parameters like SNMP credentials. This could result in widespread disruption to critical power infrastructure, potential hardware damage, and loss of visibility into operational environments.
Remediation
Immediate Action: Review the official ZTE support portal for the latest firmware release and apply the update to all affected ZXDU68 S202 units immediately.
Proactive Monitoring: Monitor system logs for unauthorized access attempts, unexpected service restarts, or abnormal command execution patterns originating from the management network.
Compensating Controls: Restrict network access to the management interfaces of these devices to trusted management subnets only, and implement strict firewall rules to prevent unauthorized discovery or interaction.
Exploitation status
Public Exploit Available: No (unknown).
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total system takeover, administrators should prioritize the identification and patching of all impacted ZTE modules. If immediate patching is not feasible, isolate the management interfaces from all non-essential network traffic to reduce the attack surface until the vendor-supplied firmware update can be deployed.
More ZTE CVEs
Sources
Originally found and disclosed by Muhammad Dio Pratama, per the CVE Program record.