PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product
Summary
| CVE | CVE-2026-49004 |
|---|---|
| State | PUBLISHED |
| Assigner | zte |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-05 07:16:37 UTC |
| Updated | 2026-08-26 16:55:49 UTC |
| Description | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
EPSS: 0.006890000 probability, percentile 0.493490000 (date 2026-08-09)
Problem Types: CWE-89 | CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
LowAvailability
LowCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ZTE | NX799J Red Magic 11 Air | affected GEN_CN_NX799JV1.0.0B15 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405 | [email protected] | support.zte.com.cn | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Littlenine and Sunflower (en)
There are currently no legacy QID mappings associated with this CVE.