{"schema_version":1,"title":"Zte vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Zte: 4 in the last 7 days and 7 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86555, was published on 20 September 2026.","url":"https://junglewise.ai/threats/vendors/zte","json_url":"https://junglewise.ai/threats/vendors/zte.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/zte","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":16,"critical":2,"exploited":0,"last_7_days":4,"last_30_days":6,"last_90_days":7,"last_365_days":16},"latest":[{"cve":"CVE-2026-86555","cvss":6.2,"epss":0.002,"slug":"cve-2026-86555-the-zte-smartlife-application-has-a-hardcoded-key-the-key-used-to","title":"ZTE SmartLife hardcoded encryption key in account credentials","severity":"medium","exploited":false,"published_at":"2026-09-20T10:16:52.797+00:00","url":"https://junglewise.ai/threats/cve-2026-86555-the-zte-smartlife-application-has-a-hardcoded-key-the-key-used-to"},{"cve":"CVE-2026-86554","cvss":4.3,"epss":0.0033,"slug":"cve-2026-86554-smartlife-app-dynamically-generates-brand-new-smartlife","title":"ZTE SmartLife app account enumeration via exposed credentials","severity":"medium","exploited":false,"published_at":"2026-09-20T08:16:50.95+00:00","url":"https://junglewise.ai/threats/cve-2026-86554-smartlife-app-dynamically-generates-brand-new-smartlife"},{"cve":"CVE-2026-86553","cvss":8.8,"epss":0.0052,"slug":"cve-2026-86553-smartlife-app-dynamically-generates-fresh-smartlife-application","title":"ZTE SmartLife app authentication bypass in account verification","severity":"high","exploited":false,"published_at":"2026-09-20T04:17:06.24+00:00","url":"https://junglewise.ai/threats/cve-2026-86553-smartlife-app-dynamically-generates-fresh-smartlife-application"},{"cve":"CVE-2026-86552","cvss":5.4,"epss":0.0036,"slug":"cve-2026-86552-smartlife-app-dynamically-generates-brand-new-smartlife","title":"ZTE SmartLife authentication bypass in account registration","severity":"medium","exploited":false,"published_at":"2026-09-20T04:17:02.84+00:00","url":"https://junglewise.ai/threats/cve-2026-86552-smartlife-app-dynamically-generates-brand-new-smartlife"},{"cve":"CVE-2026-86550","cvss":6.5,"epss":0.0046,"slug":"cve-2026-86550-nubrowser-uxss-in-intent-protocol-handler","title":"NuBrowser UXSS in intent:// protocol handler","severity":"medium","exploited":false,"published_at":"2026-09-08T09:18:21.747+00:00","url":"https://junglewise.ai/threats/cve-2026-86550-nubrowser-uxss-in-intent-protocol-handler"},{"cve":"CVE-2026-49003","cvss":9.6,"epss":0.024,"slug":"cve-2026-49003-zte-monitoring-module-command-injection","title":"ZTE monitoring module command injection","severity":"critical","exploited":false,"published_at":"2026-08-31T10:16:49.963+00:00","url":"https://junglewise.ai/threats/cve-2026-49003-zte-monitoring-module-command-injection"},{"cve":"CVE-2026-9668","cvss":6.3,"epss":0.0079,"slug":"cve-2026-9668-zte-iccp-sql-injection-authentication-bypass","title":"ZTE ICCP SQL injection authentication bypass","severity":"medium","exploited":false,"published_at":"2026-08-26T08:16:46.83+00:00","url":"https://junglewise.ai/threats/cve-2026-9668-zte-iccp-sql-injection-authentication-bypass"},{"cve":"CVE-2026-49002","cvss":9.1,"slug":"cve-2026-49002-zte-improper-access-control-in-system-configuration","title":"ZTE improper access control in system configuration","severity":"critical","exploited":false,"published_at":"2026-05-27T09:16:32.253+00:00","url":"https://junglewise.ai/threats/cve-2026-49002-zte-improper-access-control-in-system-configuration"},{"cve":"CVE-2026-49001","cvss":5.3,"slug":"cve-2026-49001-zte-products-cross-site-request-forgery","title":"ZTE Products Cross-Site Request Forgery","severity":"medium","exploited":false,"published_at":"2026-05-27T08:16:44.46+00:00","url":"https://junglewise.ai/threats/cve-2026-49001-zte-products-cross-site-request-forgery"},{"cve":"CVE-2026-44409","cvss":5.7,"slug":"cve-2026-44409-zte-mu5250-information-disclosure-due-to-improper-access-control","title":"ZTE MU5250 information disclosure due to improper access control","severity":"medium","exploited":false,"published_at":"2026-05-22T05:16:26.35+00:00","url":"https://junglewise.ai/threats/cve-2026-44409-zte-mu5250-information-disclosure-due-to-improper-access-control"},{"cve":"CVE-2026-44408","cvss":6.3,"slug":"cve-2026-44408-zte-mu5250-unauthorized-access-in-web-interface","title":"ZTE MU5250 unauthorized access in web interface","severity":"medium","exploited":false,"published_at":"2026-05-19T09:16:20.02+00:00","url":"https://junglewise.ai/threats/cve-2026-44408-zte-mu5250-unauthorized-access-in-web-interface"},{"cve":"CVE-2026-44407","cvss":4.7,"slug":"cve-2026-44407-zte-usmartview-format-string-vulnerability-in-cloud-pc-client","title":"ZTE uSmartview format string vulnerability in Cloud PC client","severity":"medium","exploited":false,"published_at":"2026-05-07T09:16:27.617+00:00","url":"https://junglewise.ai/threats/cve-2026-44407-zte-usmartview-format-string-vulnerability-in-cloud-pc-client"},{"cve":"CVE-2026-40004","cvss":5.5,"slug":"cve-2026-40004-zte-usmartview-privilege-escalation-via-openssl-cnf-search-path","title":"ZTE uSmartview privilege escalation via openssl.cnf search path","severity":"medium","exploited":false,"published_at":"2026-05-07T04:16:23.073+00:00","url":"https://junglewise.ai/threats/cve-2026-40004-zte-usmartview-privilege-escalation-via-openssl-cnf-search-path"},{"cve":"CVE-2026-40003","cvss":5.1,"slug":"cve-2026-40003-zte-zx297520v3-arbitrary-memory-write-in-bootrom","title":"ZTE ZX297520V3 arbitrary memory write in BootROM","severity":"medium","exploited":false,"published_at":"2026-05-07T02:16:03.453+00:00","url":"https://junglewise.ai/threats/cve-2026-40003-zte-zx297520v3-arbitrary-memory-write-in-bootrom"},{"cve":"CVE-2026-40002","cvss":5,"epss":0.0011,"slug":"cve-2026-40002-zte-red-magic-11-pro-improper-privilege-management-in-service","title":"ZTE Red Magic 11 Pro improper privilege management in service interface","severity":"medium","exploited":false,"published_at":"2026-04-17T08:16:18.12+00:00","url":"https://junglewise.ai/threats/cve-2026-40002-zte-red-magic-11-pro-improper-privilege-management-in-service"},{"cve":"CVE-2026-40436","cvss":7.1,"slug":"cve-2026-40436-zte-zxedm-iems-password-reset-vulnerability-in-cloud-ems-portal","title":"ZTE ZXEDM iEMS password reset vulnerability in cloud EMS portal","severity":"high","exploited":false,"published_at":"2026-04-13T07:16:50.393+00:00","url":"https://junglewise.ai/threats/cve-2026-40436-zte-zxedm-iems-password-reset-vulnerability-in-cloud-ems-portal"}],"vendor":{"hub":true,"name":"Zte","slug":"zte","homepage":"https://www.zte.com.cn/global/","description":"A global provider of telecommunications equipment, network solutions, and mobile devices.","url":"https://junglewise.ai/threats/vendors/zte"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-49003","cvss":9.6,"epss":0.024,"slug":"cve-2026-49003-zte-monitoring-module-command-injection","title":"ZTE monitoring module command injection","severity":"critical","exploited":false,"published_at":"2026-08-31T10:16:49.963+00:00","url":"https://junglewise.ai/threats/cve-2026-49003-zte-monitoring-module-command-injection"},{"cve":"CVE-2026-49002","cvss":9.1,"slug":"cve-2026-49002-zte-improper-access-control-in-system-configuration","title":"ZTE improper access control in system configuration","severity":"critical","exploited":false,"published_at":"2026-05-27T09:16:32.253+00:00","url":"https://junglewise.ai/threats/cve-2026-49002-zte-improper-access-control-in-system-configuration"},{"cve":"CVE-2026-86553","cvss":8.8,"epss":0.0052,"slug":"cve-2026-86553-smartlife-app-dynamically-generates-fresh-smartlife-application","title":"ZTE SmartLife app authentication bypass in account verification","severity":"high","exploited":false,"published_at":"2026-09-20T04:17:06.24+00:00","url":"https://junglewise.ai/threats/cve-2026-86553-smartlife-app-dynamically-generates-fresh-smartlife-application"},{"cve":"CVE-2026-40436","cvss":7.1,"slug":"cve-2026-40436-zte-zxedm-iems-password-reset-vulnerability-in-cloud-ems-portal","title":"ZTE ZXEDM iEMS password reset vulnerability in cloud EMS portal","severity":"high","exploited":false,"published_at":"2026-04-13T07:16:50.393+00:00","url":"https://junglewise.ai/threats/cve-2026-40436-zte-zxedm-iems-password-reset-vulnerability-in-cloud-ems-portal"},{"cve":"CVE-2026-86550","cvss":6.5,"epss":0.0046,"slug":"cve-2026-86550-nubrowser-uxss-in-intent-protocol-handler","title":"NuBrowser UXSS in intent:// protocol handler","severity":"medium","exploited":false,"published_at":"2026-09-08T09:18:21.747+00:00","url":"https://junglewise.ai/threats/cve-2026-86550-nubrowser-uxss-in-intent-protocol-handler"},{"cve":"CVE-2026-9668","cvss":6.3,"epss":0.0079,"slug":"cve-2026-9668-zte-iccp-sql-injection-authentication-bypass","title":"ZTE ICCP SQL injection authentication bypass","severity":"medium","exploited":false,"published_at":"2026-08-26T08:16:46.83+00:00","url":"https://junglewise.ai/threats/cve-2026-9668-zte-iccp-sql-injection-authentication-bypass"},{"cve":"CVE-2026-44408","cvss":6.3,"slug":"cve-2026-44408-zte-mu5250-unauthorized-access-in-web-interface","title":"ZTE MU5250 unauthorized access in web interface","severity":"medium","exploited":false,"published_at":"2026-05-19T09:16:20.02+00:00","url":"https://junglewise.ai/threats/cve-2026-44408-zte-mu5250-unauthorized-access-in-web-interface"},{"cve":"CVE-2026-86555","cvss":6.2,"epss":0.002,"slug":"cve-2026-86555-the-zte-smartlife-application-has-a-hardcoded-key-the-key-used-to","title":"ZTE SmartLife hardcoded encryption key in account credentials","severity":"medium","exploited":false,"published_at":"2026-09-20T10:16:52.797+00:00","url":"https://junglewise.ai/threats/cve-2026-86555-the-zte-smartlife-application-has-a-hardcoded-key-the-key-used-to"},{"cve":"CVE-2026-44409","cvss":5.7,"slug":"cve-2026-44409-zte-mu5250-information-disclosure-due-to-improper-access-control","title":"ZTE MU5250 information disclosure due to improper access control","severity":"medium","exploited":false,"published_at":"2026-05-22T05:16:26.35+00:00","url":"https://junglewise.ai/threats/cve-2026-44409-zte-mu5250-information-disclosure-due-to-improper-access-control"},{"cve":"CVE-2026-40004","cvss":5.5,"slug":"cve-2026-40004-zte-usmartview-privilege-escalation-via-openssl-cnf-search-path","title":"ZTE uSmartview privilege escalation via openssl.cnf search path","severity":"medium","exploited":false,"published_at":"2026-05-07T04:16:23.073+00:00","url":"https://junglewise.ai/threats/cve-2026-40004-zte-usmartview-privilege-escalation-via-openssl-cnf-search-path"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[]}