CVE-2026-86555: ZTE Smartlife

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

Affected products

Published 2026-09-20. Last modified 2026-09-22.