Junglewise Threat Intelligence

CVE-2026-49000: ZTE insecure password scheme in cryptographic implementation

CVE-2026-49000 · Severity: medium · CVSS 5.3 · Published 2026-05-27

Vendors: Zte.

Executive brief

A vulnerability exists in a ZTE product due to the use of an insecure password management scheme. This flaw could allow an attacker to potentially access sensitive information or tamper with data by exploiting weak encryption or hard-coded keys. While the specific product is not named in the advisory, such issues generally compromise the confidentiality and integrity of the affected system.

Technical details

The vulnerability is classified as a cryptographic issue (CWE-310) within a ZTE product. It stems from an insecure password scheme, which may include the use of weak encryption algorithms, improper key management, or hard-coded cryptographic keys. An attacker with high privileges could potentially exploit this over a network, though the attack complexity is high and requires user interaction. Successful exploitation could lead to data leakage or unauthorized data tampering. The advisory was issued by ZTE Corporation, though specific affected models or firmware versions were not detailed in the primary NVD record.

Affected products

  • ZTE Unknown Product

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References