Firmware Vulnerability in ZTE Devices Exposes TLS Credentials
CVE-2026-49006

5.3MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-49006?

A security flaw exists in the firmware of ZTE devices, allowing unauthorized attackers to access unencrypted information. This vulnerability enables the extraction of TLS transmission credentials, posing an increased risk of data interception and malicious activity in network communications.

Affected Version(s)

F689 ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Victor Mota
.