CVE-2026-49003
largeUnauthenticated Command Injection in ZTE Power System Monitoring Module
ZTE's power system monitoring software contains an unauthenticated command injection flaw (classified by ZTE's PSIRT as CWE-287, improper authentication) that is reachable from an adjacent network, such as a site or management LAN. An attacker on that network can send crafted input to the monitoring interface to delete core system runtime files, crashing and paralyzing the monitoring module. Successful exploitation also yields root privileges, letting the attacker steal configuration passwords such as SNMP credentials and tamper with critical system parameters. Because the impact extends to overall power-system operation, operators running ZTE power systems with this monitoring module at telecom or equipment-room sites are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.8% chance of exploitation within 30 days (54th percentile), so no in-the-wild exploitation is documented despite the critical 9.6 severity.
What to do: Because no affected versions or fixed releases are listed in the source data, check ZTE's PSIRT advisory for CVE-2026-49003 and apply the vendor patch to affected power-system monitoring software. Until patched, restrict access to the monitoring interface on the management LAN (ACLs/segmentation) and rotate SNMP community strings and other configuration passwords that may have been harvested. Treat monitoring-module crashes or unexpected parameter changes as indicators of compromise and audit system configurations for tampering.
| ZTE Power system monitoring module (power system software) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.