Hardcoded Key Vulnerability in ZTE SmartLife Application
CVE-2026-86555

6.2MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-86555?

The ZTE SmartLife application contains a vulnerability where a hardcoded encryption key is stored in plaintext within the codebase. This key is critical for decrypting account server information. If an attacker gains access to this hardcoded key, they can easily decrypt sensitive data associated with user accounts, leading to potential data breaches and unauthorized access to personal information.

Affected Version(s)

SmartLife ZTE_SL_V2.8.2_ABROAD and earlier versions

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mina Nageh Salama Zekry
.