CVE-2026-49008 PUBLISHED

Integrity‑check credential leakage vulnerability in an application function of ZTE F689 product

Assigner: zte
Reserved: 27.05.2026 Published: 07.08.2026 Updated: 07.08.2026

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor ZTE
Product F689
Versions Default: unaffected
  • Version ZXHN F680V9.0.10P6N1,ZXHN F680V9.0.10P4N4,ZXHN F680V9.0.10P4N5,ZXHN F680V9.0.10P4N9,ZXHN F680V9.0.10P4N10,ZXHN F680V9.0.10P1N12,ZXHN F680V9.0.10P1N13 is affected

Credits

  • Victor Mota finder

References

Problem Types

  • CWE-321 Use of hard-coded cryptographic key CWE

Impacts

  • CAPEC-191 Read Sensitive Constants Within an Executable