ZeroHour

CVE-2026-49003

large

Unauthenticated Command Injection in ZTE Power System Monitoring Module

CVSS 3.1
9.6 critical
EPSS
<1%p54
Published
()
Modified
AI analysis

ZTE's power system monitoring software contains an unauthenticated command injection flaw (classified by ZTE's PSIRT as CWE-287, improper authentication) that is reachable from an adjacent network, such as a site or management LAN. An attacker on that network can send crafted input to the monitoring interface to delete core system runtime files, crashing and paralyzing the monitoring module. Successful exploitation also yields root privileges, letting the attacker steal configuration passwords such as SNMP credentials and tamper with critical system parameters. Because the impact extends to overall power-system operation, operators running ZTE power systems with this monitoring module at telecom or equipment-room sites are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.8% chance of exploitation within 30 days (54th percentile), so no in-the-wild exploitation is documented despite the critical 9.6 severity.

What to do: Because no affected versions or fixed releases are listed in the source data, check ZTE's PSIRT advisory for CVE-2026-49003 and apply the vendor patch to affected power-system monitoring software. Until patched, restrict access to the monitoring interface on the management LAN (ACLs/segmentation) and rotate SNMP community strings and other configuration passwords that may have been harvested. Treat monitoring-module crashes or unexpected parameter changes as indicators of compromise and audit system configurations for tampering.

Affected
ZTE Power system monitoring module (power system software)
Estimated exposure
large≈ tens of thousands of telecom power-site deployments (estimated from ZTE's global power-equipment footprint; no published counts) — ZTE is a major global supplier of telecom power systems whose monitoring modules are typically deployed at operator equipment rooms, implying an installed base on the order of tens of thousands of sites, though no authoritative…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.

Weakness
CWE-287
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.