Executive brief
The ZTE SmartLife application stores a hardcoded encryption key in its source code that is used to protect account server information. An attacker who obtains this key can decrypt the server credentials, potentially gaining unauthorized access to backend systems and user account data.
Technical details
The vulnerability exists due to a hardcoded cryptographic key stored in plaintext within the application code. This key is used to decrypt account server information, and exposure of the key enables decryption of sensitive credentials without authentication. The vulnerability requires the attacker to obtain access to the application code or binary to extract the key.
Affected products
- ZTE SmartLife
Timeline
- 2026-09-20: disclosed