{"id":"CVE-2026-86555","title":"The ZTE SmartLife application has a hardcoded key","summary":"The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-798"],"vendor":"ZTE","product":"SmartLife","affected":["SmartLife ZTE_SL_V2.8.2_ABROAD and earlier versions"],"published":"2026-09-20","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:14.653","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86555","references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159007054","label":"psirt@zte.com.cn"}],"tags":["nvd","cve.org"],"epss":0.00183,"epssPercentile":0.08093,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T18:05:35.918299Z"},"ingestedAt":"2026-09-20T10:19:44.905Z","slug":"CVE-2026-86555","body":"## Overview\n\nThe ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}