CVE-2026-49000 PUBLISHED

Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product

Assigner: zte
Reserved: 27.05.2026 Published: 27.05.2026 Updated: 27.05.2026

An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS Score: 7

Product Status

Vendor ZTE
Product ZXUniPOS NDS-LTE
Versions Default: unaffected
  • Version V24.30.40CP02 and earlier versions is affected
  • Version V24.40.40 and earlier versions is affected

Credits

  • Venom Nguyen finder

References

Problem Types

  • CWE-310 Cryptographic Issues CWE

Impacts

  • CAPEC-97 Cryptanalysis