CVE-2026-49007 PUBLISHED

Information leakage vulnerability in ZTE F689 product

Assigner: zte
Reserved: 27.05.2026 Published: 07.08.2026 Updated: 07.08.2026

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor ZTE
Product F689
Versions Default: unaffected
  • Version ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13 is affected

Credits

  • Victor Mota finder

References

Problem Types

  • CWE-798 Common Weakness Enumeration-798 CWE

Impacts

  • CAPEC-191 Read Sensitive Constants Within an Executable