ZTE Terminal Product Bug Bounty Program

Update date: July 17, 2026

This program includes the following products of ZTE:

Product Type Model
Terminal product Cloud terminal: W152D
Cloud PC: uSmartView V7.25.43
Mobile Internet: MC888, MC8600
Smartphone: Z80 Ultra (vulnerabilities are limited to the Nebula AIOS itself, excluding third-party components and native Android environment vulnerabilities)

1. Vulnerability Bounties and Rating Standards

1.1 Vulnerability Bounties

Rewards are determined according to the impact (severity, influence, score,etc.) of the vulnerability on the product and the clarity of the vulnerability report.

Severity Critical High Medium Low
Bounty $500~$5000 $250~$1250 $50~$250 $15~$50

1.2 Vulnerability Rating Standards

【Critical】

1) Vulnerabilities that can be used to directly obtain the permissions of the core systems (management and control systems that can manage a large number of servers such as core control systems, domain control systems, service distribution systems, bastion hosts, firewalls, etc.) or the core servers, including but not limited to: upload web shell, arbitrary code execution, remote command execution, parse-server vulnerabilities, file inclusion vulnerabilities, remote buffer overflow, Virtual machine escape, or SQL injection to obtain system permissions;

2) Serious information leak vulnerabilities of core systems, including but not limited to: SQL injection of core DB, important sensitive information leak of a large number of users (Including at least three of the following sensitive fields: Name/ID card, bank card information, phone number/ email, password, and address), internal core data breach of enterprises, or configuration data and log data of core equipment;

3) Serious logical design error or process defect of core system, including but not limited to: Modification in batches of arbitrary account password vulnerability, fund consumption of arbitrary account and payment vulnerability for arbitrary amount modification, etc., that cause great losses to users and companies;

4) Vulnerabilities that can remotely cause permanent and serious impact on the availability of core systems and core servers, including but not limited to: the DoS vulnerabilities that directly cause the breakdown of the core system services and core servers.

【High】

1) Vulnerabilities that can be used to directly obtain the permissions of important service servers, including but not limited to: upload webshell,  arbitrary code execution, and arbitrary command execution, parse-server, file inclusion, remote buffer overflow, or SQL injection;

2) Vulnerabilities that directly lead to important information leak, including but not limited to: SQL injection vulnerability of important DB, file traversal, arbitrary file read, and leak of a large number of source code or compressed packages of important services;

3) Vulnerabilities that affect users in a wide range, including but not limited to: stored XSS that can cause automatic propagation of core services, stored XSS that can obtain administrator authentication information and can successfully exploit, CSRF that can cause worms, XSS vulnerabilities of important client products that can obtain sensitive information or perform sensitive operations;

4) Serious broken access control, including but not limited to: weak passwords or bypassing authentication to access important background management system, stealing users' important identity information in batches, obtaining permissions of ordinary mobile clients in remote mode, and executing arbitrary commands and code;

5) Serious logical design error or process defects, such as arbitrary password reset vulnerability of important systems;

6) Vulnerabilities that can remotely cause permanent and serious impact on the availability of important service systems and important servers, including but not limited to: the DoS vulnerabilities that directly cause the breakdown of important system services and servers.

【Medium】

1) Vulnerabilities that require interaction to obtain user identity information, including but not limited to: CSRF for important sensitive operations and stored XSS for common services;

2) Serious information leak, including but not limited to: SQL injection that can obtain insensitive data, SSRF vulnerability without echo reply, leak of source code or compression packages that contain sensitive information (such as DB connection passwords), leak of sensitive authentication keys stored locally ( effective use is required), etc.;

3) Common broken access control, including but not limited to: bypassing restrictions on access to non-important background management system, incorrect direct object references, bypassing restrictions on user data modification, performing user operations, reading user information, and tampering of Non-Key Services;

4) Common logical design error, including but not limited to: vulnerabilities caused by the successful blasting of system sensitive operations such as verification code logic errors that cause arbitrary account login and arbitrary password retrieval, password reset or account login through four-digit verification code blasting, and unlimited SMS sending, etc.;

5) Arbitrary file operation vulnerabilities, including but not limited to: arbitrary file read/write/delete/download operations, arbitrary file upload, such as uploading html that causes stored XSS.

【Low】

1) Causes application-level crashes, or merely mentions the possibility of MITM or SQL injection without specifying exploitation methods;

2) If a vulnerability is exploited by deceiving users (for example, phishing or clicks) in content for more than two times, no reward will be given for the vulnerability that needs to be exploited.

3) Third-party vulnerabilities that affect not only ZTE equipment but also equipment from other vendors;

4) Prior to reporting to ZTE, the technical details of the vulnerability (such as POC information) have already been disclosed, including but not limited to websites, social media, mailing lists, public presentations, instant messaging groups, etc.; such vulnerabilities are ineligible for the reward program;

5) In scenarios where multiple individuals or the same individual submit duplicate vulnerabilities, the first submitted vulnerability report is considered valid, while others are deemed ineligible;

6) Reports generated directly by AI without human reproduction or without providing screenshots of valid verification results will be directly rejected by the platform, and no explanation for the rejection will be provided.

7) We will not provide rewards for vulnerabilities that require specific privileges to be successfully exploited and cause impact, where those privileges themselves can produce the same effect;

8) Vulnerabilities outside the models listed in the reward program are not eligible for rewards;

9) Software functional errors with no security impact;

10) Minor information leakage, including but not limited to: absolute path disclosure, phpinfo exposure, SVN/CVS information leakage, web directory traversal, system path traversal, directory listing, and local logs containing sensitive information;

11) Vulnerabilities that pose security risks but are difficult to exploit, including but not limited to: sensitive security vulnerabilities requiring continuous user interaction, hard-to-exploit SQL injection points, and client-side denial of service;

12) Unexploitable vulnerabilities, including but not limited to vulnerability scan reports without proof of actual harm, CSRF attacks without sensitive operations, meaningless source code leaks, and internal network IP address or domain name leaks;

13) Other issues that do not directly reflect the existence of vulnerabilities, including but not limited to issues based solely on user speculation;

14) Iterating through mobile numbers to send SMS, iterate through usernames (email addresses) to check for registration status, email bombing, and meaningless or non-impactful unauthorized access.

15) Low-impact local Denial-of-Service (DoS) attacks;

16) Temporary denial-of-service attacks causing system hangs or device reboots (exceptions may be evaluated for cases where service processes hang or exit abnormally);

17) All violent and forceful denial-of-service attacks;

18) Reports based on ZTE confidential information obtained through illegal means;

2. Report Requirements

In order to reproduce the vulnerability, your report must contain a detailed vulnerability description and a complete POC or Exploit.

2.1 Report description requirements

1) Vulnerability description, which needs to include the vulnerability types, the causes, the methods of exploitation, and the potential risks;

2) Affected product or service name, module name, detailed version information, and specific vulnerability location;

3) Describe the detailed steps required for reproducing the vulnerability by using texts, screenshots, graphics, etc. Describe the reproducing process step by step (recommend to submit a vulnerability reproduction video).

4) Strict manual verification: Vulnerability reports generated by AI-assisted or automated mining must undergo manual verification before submission. Please ensure that you have completed the assessment and reproduction of the report's authenticity and severity, and provide detailed manual verification results in the report, including but not limited to:
a) Vulnerability hazard description
b) Detailed steps for reproduction
c) Complete POC
d) Key steps and result screenshots

2.2 POC or Exploit requirements

1) Provide a complete and compilable POC or Exploit. The POC or Exploit can be used to successfully verify the reported vulnerability;

2) Compilation and running environment description, including: compiler name, compiler version, compilation options, operating system version, and other necessary information;

3) The running result of POC or Exploit should be consistent with that described in your report;

A vulnerability report should include the detailed vulnerability description, proof of harm, and POC. Reports that are too simple or have no proof of harm will be degraded or ignored.

3. Legal Information

The following rules should be followed for your participation in our bug bounty program and reporting vulnerabilities to us:

1) You shall only exploit, investigate or attack vulnerabilities within your own accounts or devices;

2) Your testing activities must not negatively impact the availability or performance of ZTE's products or services, break ZTE online service, attack ZTE's internal or external servers, nor cause damage of data or physical assets;

3) Do not download sensitive service data during the test, including but not limited to source code or users’ personal data, etc. The information must not be used, disclosed, stored, or recorded in any form. If unknown download happens, an timely feedback and explanation shall be made and the file shall be deleted;

4) Without ZTE's written approval, do not disclose any details about the security vulnerabilities of ZTE's products or services to any third party;

5) Do not intentionally making and spreading malicious programs such as computer viruses;

6) Do not infringe any third party's rights (including intellectual property rights);

7) You are not an employee or outsourced employee or contractor of ZTE and its subsidiaries, or an immediate family member of an employee or outsourced employee or contractor of ZTE.

If you use the security test as an excuse to exploit the vulnerability information to damage user interests, affect normal service operations, or steal user data, which causes us losses or violates laws and regulations, ZTE Corporation reserves the right to pursue legal responsibilities. 

4. Reward Payment

1) The rewards amount ranges from $15 to $5000 for qualified vulnerabilities. Each vulnerability will be rewarded based on the severity, complexity of attack, impact scope, and report quality;

2) The reproduced vulnerabilities will be rewarded through ZTE Corporation bank account transfer. In order to complete the bounty payment, we need to collect your nationality, city, real name, mobile phone number, ID card number, family or company address, bank card number, name of the deposit bank, and bank SWIFT code, etc. We promise you that the collection of these information will only be used for our payment and will not be used for other purposes;  

3) In order to comply with applicable tax-related legal requirements, we have withheld and paid personal income tax when paying you bonus.

5. Dispute Resolution

In the process of handling vulnerabilities, if the reporter has objections to the handling process, vulnerability assessment or vulnerability scoring, please send email to psirt@zte.com.cn,
our staffs will answer your questions as soon as possible.

6. Others

1) We will regularly update the list of products/services included in the reward scope;

2) Irrelevant security questions submitted will not be answered and processed, and the response time during holidays will be delayed;

3) This bug bounty program shall come into force from the date of issuance. ZTE owns the full right to determine the severity level, the reward amount and the payment process. ZTE also remains the rights to suspend the bug bounty program at any time;

4) ZTE PSIRT has the final right to interpret all the above terms.

7. Revision Record

V1.0 2026.7.17    initial release