These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements, potentially leading to the theft of local privacy data. This vulnerability has a CVSS score of 3.9 and a LOW severity rating. Affected users should prioritize patching and review the app's database security. The CVE record was published on 2026-08-05T09:18:16.187Z and has not been modif [truncated]
The CVE-2026-49004 record details a critical vulnerability in the built-in PostgreSQL service of a mobile device, which suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission [truncated]
The CVE record for CVE-2026-40000 was published on 2026-07-27T10:16:37.907Z and has not been modified since then. This CVE describes a vulnerability in the FilePreViewActivity of ZTE File Manager, which allows third-party applications to access arbitrary files with elevated privileges. This could potentially expose sensitive data in system directories such as /data/data and /data/local/tmp on unrooted dev [truncated]
A medium-severity vulnerability (CVSS 5.3) involving insecure cryptographic practices was published on May 27, 2026. The issue stems from improper selection of encryption algorithms, inadequate key management, or flawed implementation—such as hard-coded keys or weak encryption—that could lead to data leakage or tampering. The vulnerability is associated with ZTE based on vendor evidence in the source refe [truncated]
CVE-2026-48999 is a stored cross-site scripting (XSS) vulnerability with a CVSS 3.1 score of 5.3 (Medium). The vulnerability allows attackers to inject malicious JavaScript into target systems, which executes in victims' browsers when they access affected pages. This enables session hijacking, cookie theft, and page content tampering. The stored nature of the attack provides broad scope and strong conceal [truncated]
A business logic vulnerability in ZTE products allows authenticated administrators to exploit legitimate application functions in unintended ways. The flaw stems from improper implementation of business logic controls (CWE-1240), enabling malicious use of authorized capabilities outside their designed scope. The vulnerability requires high privileges (PR:H) with network access, and has low impact on integ [truncated]
CVE-2026-44409 is a medium-severity information disclosure issue affecting ZTE MU5250. The CVE description says improper configuration of the access control mechanism can let attackers obtain information without authorization. NVD records the issue with CVSS 3.1 vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating adjacent-network access, low privileges, no user interaction, and high confidentiality impact.
A medium-severity unauthorized access vulnerability exists in the ZTE MU5250, a mobile broadband device. The vulnerability stems from improper permission controls on the Web management interface, allowing an attacker with local network access and low privileges to modify device configuration without proper authorization. The CVSS 3.1 vector (AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H) indicates attack complexity [truncated]
CVE-2026-40002 is a medium-severity vulnerability in Red Magic 11 Pro (NX809J) that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties. This vulnerability has a CVSS score [truncated]