ZTE Z80 Ultra Build B28MR2 Fixes Five Information-Disclosure Flaws

P2 — VALIDATE AND UPDATELow to Medium · 3.3 / 5.5 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

ZTE published five PSIRT bulletins for CVE-2026-108502 through CVE-2026-108506 in the Z80 Ultra NX741J. Builds GEN_ZTE_PQ85A01V1.0.0B27 and earlier are affected; ZTE resolves the issues in GEN_ZTE_PQ85A01V1.0.0B28MR2 and directs customers to its support center for the update.

Identify NX741J Devices And Obtain The Supported B28MR2 Build

What to do now: Inventory ZTE Z80 Ultra NX741J devices, compare the exact installed build with B27 and earlier, obtain B28MR2 or a supported superseding build through ZTE, validate deployment, review untrusted-application exposure, and retain evidence.

Open the authoritative advisory

Last verified: 2026-10-10 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeZTE Z80 Ultra, product identifier NX741J
AdvisorySA-202610-1743956 / SA-202610-1743919 / SA-202610-1743926 / SA-202610-1743952 / SA-202610-1743906
CVEsCVE-2026-108502, CVE-2026-108503, CVE-2026-108504, CVE-2026-108505, CVE-2026-108506
Authoritative release date2026-10-10; the five vendor bulletins display release times without an explicit time-zone label, while the latest ZTE CNA record was published at 09:08:04.151 UTC
Authority revision date2026-10-10; ZTE records each bulletin as the initial release and states no separate revision time
Affected versionsGEN_ZTE_PQ85A01V1.0.0B27 and all prior released versions on the NX741J product
Fixed versionGEN_ZTE_PQ85A01V1.0.0B28MR2, obtained through the ZTE Global Customer Support Center
CVSS base score3.3 / 5.5 (CVSS v3.1)
CVSS severityLow to Medium
Exploitation statusNot stated by ZTE; no exploitation claim is inferred.

What Changed

ZTE published five separate PSIRT bulletins for local information-disclosure paths in Z80 Ultra system interfaces. A third-party application can hook, reflectively invoke, or receive data from insufficiently restricted interfaces and obtain device-related information. ZTE does not report active exploitation.

What To Validate Now

  1. Inventory. Locate managed ZTE Z80 Ultra devices, confirm product identifier NX741J, record the exact software build and management owner, and identify devices on which untrusted or unnecessary third-party applications are installed.
  2. Establish applicability. Treat NX741J builds GEN_ZTE_PQ85A01V1.0.0B27 and earlier as affected. Do not extend the bulletin to similarly named ZTE devices, other regional builds, or unrelated product identifiers without ZTE evidence.
  3. Remediate. Contact the ZTE Global Customer Support Center and obtain GEN_ZTE_PQ85A01V1.0.0B28MR2 or a ZTE-supported superseding build. Use the supported delivery path and preserve recovery options.
  4. Validate. Verify the resulting NX741J build, exercise representative device and managed-application functions, confirm management and connectivity, review the third-party application inventory, and document exceptions and rollback readiness.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Mobile firmware can be model- and region-specific. Use only ZTE-supported packages and delivery paths, maintain recovery options, and verify the actual running build after installation. Severity does not establish local applicability or exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.