CVE-2026-86555

Summary

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

Affected Software

VendorProductVersion RangeStatus
ZTESmartLifeZTE_SL_V2.8.2_ABROAD and earlier versionsaffected

Weaknesses

  • CWE-798: CWE-798 Use of Hard-coded Credentials

References