CVE-2026-49006

Summary

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.

Affected Software

VendorProductVersion RangeStatus
ZTEF689ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13affected

Weaknesses

  • CWE-321: CWE-321 Use of hard-coded cryptographic key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References