SQL Injection Vulnerability in ZTE Smart Life Application
CVE-2026-8029
3.9LOW
What is CVE-2026-8029?
The ZTE Smart Life app is susceptible to an SQL injection attack, which could allow unauthorized users to execute UNION SELECT statements. This vulnerability enables attackers to access sensitive information stored in the feedback.db database, including user accounts, phone numbers, feedback content, and local debug log paths. Consequently, this could lead to significant risks involving the privacy and security of local user data. It is crucial for users and administrators to apply necessary precautions and updates to mitigate these security risks effectively.
Affected Version(s)
SmartLife ZTE_SL_V5.0.7and all prior released versions
