CVE-2026-86555
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZTE | SmartLife | ZTE_SL_V2.8.2_ABROAD and earlier versions | affected |
Weaknesses
- CWE-798: CWE-798 Use of Hard-coded Credentials
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.