CVE-2026-86555
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
20/09/2026
Last modified:
22/09/2026
Description
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
Impact
Base Score 3.x
6.20
Severity 3.x
MEDIUM


