CVE-2026-49006 PUBLISHED

TLS credential leakage vulnerability in ZTE F689 product

Assigner: zte
Reserved: 27.05.2026 Published: 07.08.2026 Updated: 07.08.2026

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor ZTE
Product F689
Versions Default: unaffected
  • Version ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13 is affected

Credits

  • Victor Mota finder

References

Problem Types

  • CWE-321 Use of hard-coded cryptographic key CWE

Impacts

  • CAPEC-191 Read Sensitive Constants Within an Executable