CVE-2026-8029 PUBLISHED

SQL Injection Vulnerability in ZTE SmartLife App

Assigner: zte
Reserved: 06.05.2026 Published: 05.08.2026 Updated: 05.08.2026

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 3.9

Product Status

Vendor ZTE
Product SmartLife
Versions Default: unaffected
  • Version ZTE_SL_V5.0.7and all prior released versions is affected

Credits

  • DHK Dark Horse finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-108 Command Line Execution through SQL Injection