Firmware Information Exposure in ZTE Devices
CVE-2026-49008

6.5MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-49008?

This vulnerability allows an attacker to access unencrypted information within the firmware of ZTE devices. By exploiting this flaw, the attacker can retrieve sensitive credentials that are crucial for the integrity verification of specific application functions. This exposure of unprotected data significantly increases the risk of unauthorized access and manipulation of application integrity, compromising the security of affected devices.

Affected Version(s)

F689 ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Victor Mota
.