These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The ZTE SmartLife application contains a hardcoded key used for decrypting account server information, which is stored in plaintext within the code. This vulnerability allows server information to be decrypted and exposed if the key is obtained. Defenders and security teams responsible for the ZTE SmartLife application should assess the exposure and secure the hardcoded key to prevent server information e [truncated]
CVE-2026-86554 debrief based on the supplied source corpus. The SmartLife app dynamically generates brand-new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. [truncated]
CVE-2026-86553 debrief based on the supplied source corpus. The SmartLife app has a high-severity vulnerability that allows an attacker to obtain the real account ID corresponding to a registered email address and reset the password of the target account. Defenders should prioritize verifying and mitigating the vulnerability to prevent potential account takeovers and unauthorized access. The vulnerability [truncated]
CVE-2026-86552 is a vulnerability in the SmartLife app that allows an attacker to register using an arbitrary email address without verification, using acquired authentication credentials. The vulnerability is caused by the dynamic generation of authentication parameters at runtime, which can be exploited by an attacker to complete registration via the backend interface /account/person/signup.serv. This v [truncated]
The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database. This low-severity vulnerability has a CVSS score of 3.3. The CVE record was published on 2026-09-20T02:16:51.310Z and has not been modified since then.
A universal cross-site scripting (UXSS) vulnerability exists in NuBrowser due to a lack of protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This vulnerability enables attackers to execute scripts within the origin of arbitrary websites, potentially leading to unauthorized actions and data breaches. Defenders s [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T09:16:58.880Z and has not been modified since then. CVE-2026-49008 allows attackers to access unencrypted information in device firmware, obtaining credentials related to application function integrity verification. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity. A [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T08:16:46.323Z and has not been modified since then. The vulnerability, CVE-2026-49006, allows attackers to access unencrypted information in device firmware, obtaining credentials related to TLS transmission. Organizations using devices with firmware that may be affected by this vulnerability sho [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T05:17:02.083Z and has not been modified since then. The root password hash of the device can be obtained through unencrypted information in the firmware. Organizations using affected devices should verify and monitor device security. The CVE Program and NIST NVD provide official records and asses [truncated]
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements, potentially leading to the theft of local privacy data. This vulnerability has a CVSS score of 3.9 and a LOW severity rating. Affected users should prioritize patching and review the app's database security. The CVE record was published on 2026-08-05T09:18:16.187Z and has not been modif [truncated]
The CVE-2026-49004 record details a critical vulnerability in the built-in PostgreSQL service of a mobile device, which suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission [truncated]
The CVE record for CVE-2026-40000 was published on 2026-07-27T10:16:37.907Z and has not been modified since then. This CVE describes a vulnerability in the FilePreViewActivity of ZTE File Manager, which allows third-party applications to access arbitrary files with elevated privileges. This could potentially expose sensitive data in system directories such as /data/data and /data/local/tmp on unrooted dev [truncated]
A medium-severity vulnerability (CVSS 5.3) involving insecure cryptographic practices was published on May 27, 2026. The issue stems from improper selection of encryption algorithms, inadequate key management, or flawed implementation—such as hard-coded keys or weak encryption—that could lead to data leakage or tampering. The vulnerability is associated with ZTE based on vendor evidence in the source refe [truncated]
CVE-2026-48999 is a stored cross-site scripting (XSS) vulnerability with a CVSS 3.1 score of 5.3 (Medium). The vulnerability allows attackers to inject malicious JavaScript into target systems, which executes in victims' browsers when they access affected pages. This enables session hijacking, cookie theft, and page content tampering. The stored nature of the attack provides broad scope and strong conceal [truncated]
A business logic vulnerability in ZTE products allows authenticated administrators to exploit legitimate application functions in unintended ways. The flaw stems from improper implementation of business logic controls (CWE-1240), enabling malicious use of authorized capabilities outside their designed scope. The vulnerability requires high privileges (PR:H) with network access, and has low impact on integ [truncated]
CVE-2026-44409 is a medium-severity information disclosure issue affecting ZTE MU5250. The CVE description says improper configuration of the access control mechanism can let attackers obtain information without authorization. NVD records the issue with CVSS 3.1 vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating adjacent-network access, low privileges, no user interaction, and high confidentiality impact.
A medium-severity unauthorized access vulnerability exists in the ZTE MU5250, a mobile broadband device. The vulnerability stems from improper permission controls on the Web management interface, allowing an attacker with local network access and low privileges to modify device configuration without proper authorization. The CVSS 3.1 vector (AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H) indicates attack complexity [truncated]
CVE-2026-40002 is a medium-severity vulnerability in Red Magic 11 Pro (NX809J) that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties. This vulnerability has a CVSS score [truncated]