ZTE Z80 Ultra Update Restricts Wi-Fi MAC Address Disclosure
Quick Answer
ZTE published SA-202609-1573076 for CVE-2026-86551 in the Z80 Ultra (NX741J). ZTE says a non-privileged program could retrieve the device's Wi-Fi MAC address and resolves the issue in build GEN_ZTE_PQ85A01V1.0.0B26MR.
Match The Exact Model And Build
What to do now: Identify managed Z80 Ultra devices by model and build, obtain the supported update through ZTE, verify the resulting build, and review whether untrusted applications were present on affected devices.
Last verified: 2026-09-20 UTC. Recheck the ZTE bulletin before changing managed devices.
Scope And Authority
| Product scope | ZTE Z80 Ultra, model NX741J |
|---|---|
| Advisory | SA-202609-1573076 |
| CVE | CVE-2026-86551 |
| Authoritative release date | 2026-09-20 01:22:42 UTC in ZTE's UTC-rendered bulletin |
| Authority revision date | 2026-09-20; initial bulletin |
| Affected versions | GEN_ZTE_PQ85A01V1.0.0B23MR3 and all prior released versions |
| Fixed version | GEN_ZTE_PQ85A01V1.0.0B26MR |
| CVSS base score | 3.3 (CVSS v3.1) |
| CVSS severity | Low |
| Exploitation status | Not stated by ZTE; no exploitation claim is inferred. |
What Changed
ZTE states that a non-privileged program could query the read-only factory_mac_address field in the Settings.Secure database and retrieve the Wi-Fi MAC address. ZTE provides no workaround in the cited bulletin and directs customers to its Global Customer Support Center for the upgraded version.
What To Validate Now
- Inventory. Confirm the device is the Z80 Ultra
NX741J; do not apply this bulletin to similarly named models without ZTE evidence. - Record. Capture the installed build, device ownership, management state, and presence of non-approved or untrusted applications.
- Remediate. Obtain
GEN_ZTE_PQ85A01V1.0.0B26MRor a supported superseding build through ZTE's documented support channel. - Validate. Confirm the post-update build, device enrollment, connectivity, Wi-Fi behavior, business applications, and security controls.
- Review. Where policy and available telemetry permit, investigate unexpected applications or access patterns without treating the vulnerability as proof of compromise.
Operational Cautions
Mobile firmware is model- and region-specific. Preserve recovery options, use only ZTE-supported packages and delivery paths, and verify the actual build after installation. CVSS severity does not establish local exposure or exploitation.
Evidence To Retain
- Asset, service, environment, and owner identifiers used for the applicability decision.
- UTC timestamps and before-and-after package, application, firmware, or build versions.
- Change approval, installation output, validation results, and any exception or rollback record.
- The authoritative advisory evidence used at the time of the decision.
Related TechGeeks Resources
Authoritative References
Correction policy: If ZTE changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

