« Volver al listado

CVE-2026-44410

Estado: AplazadaBaja (3.8)—

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44410",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44410",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T11:50:27.685849Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@zte.com.cn",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.8,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@zte.com.cn",
      "affectedData": [
        {
          "vendor": "ZTE",
          "product": "ZXUniPOS NDS-LTE",
          "versions": [
            {
              "status": "affected",
              "version": "Versions < V25.30.40"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-26T10:16:18.550",
  "references": [
    {
      "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3711746568357343383",
      "source": "psirt@zte.com.cn"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@zte.com.cn",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1240"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks."
    },
    {
      "lang": "es",
      "value": "Esta vulnerabilidad se deriva de un fallo en la lógica de negocio. Los atacantes pueden explotar funciones legítimas de la aplicación de formas no intencionadas y anómalas, desviándose de las expectativas del diseñador, para llevar a cabo ataques maliciosos."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "psirt@zte.com.cn"
}