CVE-2026-49003 is a critical command injection vulnerability affecting ZTE power monitoring systems. Attackers can exploit this flaw to delete core system runtime files, causing the monitoring module to crash and become non-functional. The vulnerability also allows attackers to escalate privileges to root level, enabling theft of sensitive configuration credentials including SNMP passwords. With root access and stolen credentials, attackers can tamper with critical system parameters, potentially triggering abnormal operation of entire power systems. This represents a significant threat to critical infrastructure, combining availability impact (crash) with confidentiality (credential theft) and integrity (parameter tampering) impacts. ZTE has published a security bulletin addressing this issue.