Executive brief
A vulnerability exists in a ZTE product due to the use of an insecure password management scheme. This flaw could allow an attacker to potentially access sensitive information or tamper with data by exploiting weak encryption or hard-coded keys. While the specific product is not named in the advisory, such issues generally compromise the confidentiality and integrity of the affected system.
Technical details
The vulnerability is classified as a cryptographic issue (CWE-310) within a ZTE product. It stems from an insecure password scheme, which may include the use of weak encryption algorithms, improper key management, or hard-coded cryptographic keys. An attacker with high privileges could potentially exploit this over a network, though the attack complexity is high and requires user interaction. Successful exploitation could lead to data leakage or unauthorized data tampering. The advisory was issued by ZTE Corporation, though specific affected models or firmware versions were not detailed in the primary NVD record.
Affected products
- ZTE Unknown Product
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory