The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 20 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zte
Zte smartlife |
|
| Vendors & Products |
Zte
Zte smartlife |
Sun, 20 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. | |
| Title | Hardcoded Key Vulnerability in ZTE SmartLife APP | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-09-20T09:15:43.868Z
Reserved: 2026-09-08T02:55:56.712Z
Link: CVE-2026-86555
No data.
Status : Received
Published: 2026-09-20T10:16:52.797
Modified: 2026-09-20T10:16:52.797
Link: CVE-2026-86555
No data.
OpenCVE Enrichment
Updated: 2026-09-20T10:30:17Z
Weaknesses