CVE-2026-86555: Hardcoded Key Vulnerability in ZTE SmartLife APP
Published Sep 20, 2026
·Updated
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
Affected Software
1 affected component
ZTE SmartLife app
Event History
Sep 20, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker needs to obtain the hardcoded decryption key from the ZTE SmartLife application code. That key can then be used to decrypt account server information stored or handled by the application.
2
What information is exposed if the issue is exploited?
The disclosed impact is exposure of account server information after it is decrypted with the hardcoded key. The available information does not specify which individual server fields or account data elements are included.