SQL Injection Vulnerability in ZTE Smart Life Application
CVE-2026-8029

3.9LOW

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-8029?

The ZTE Smart Life app is susceptible to an SQL injection attack, which could allow unauthorized users to execute UNION SELECT statements. This vulnerability enables attackers to access sensitive information stored in the feedback.db database, including user accounts, phone numbers, feedback content, and local debug log paths. Consequently, this could lead to significant risks involving the privacy and security of local user data. It is crucial for users and administrators to apply necessary precautions and updates to mitigate these security risks effectively.

Affected Version(s)

SmartLife ZTE_SL_V5.0.7and all prior released versions

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DHK Dark Horse
.