CVE-2026-49004 Details
Description
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
A vulnerability exists in the built-in PostgreSQL service on the ZTE Red Magic 11 Air (NX799J) mobile device, due to misconfiguration and command injection flaws. The service operates with root privileges, listens on a specific port, and is secured by weak credentials. It allows local attackers to exploit the COPY FROM PROGRAM syntax to bypass Android's permission sandbox, potentially leading to full root access.
Users can upgrade to ZTE Red Magic 11 Air version GEN_CN_NX799JV1.0.0B16 to address this vulnerability. For assistance, contact the ZTE Global Customer Support Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ZTE NX799J | GEN_CN_NX799JV1.0.0B15 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion