CVE-2026-44409 Details
Description
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.
An information disclosure vulnerability exists in the ZTE MU5250 due to improper access control configuration. This allows attackers to obtain sensitive information without authorization, leading to a risk of information leakage.
Users can upgrade to ZTE MU5250 version BD_FLYMODEMMU5250V1.0.0B28 to address this vulnerability. Devices that support automatic updates will receive a notification to upgrade. For those who do not receive an update prompt, please consult the relevant service provider for update information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3711746568357343342 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zte mu5250 firmware | 1.0.0b27 |
CPE
Remediation
| |
| zte mu5250 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 22, 2026 | New CVE Received | [email protected] |