---
id: CVE-2026-86555
title: The ZTE SmartLife application has a hardcoded key
summary: >-
  The ZTE SmartLife application has a hardcoded key. The key used to decrypt
  account server information is stored in plaintext in the code. Once the key is
  obtained, the server information can be decrypted, thus exposing it.
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-798
vendor: ZTE
product: SmartLife
affected:
  - SmartLife ZTE_SL_V2.8.2_ABROAD and earlier versions
published: '2026-09-20'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86555'
references:
  - url: >-
      https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159007054
    label: psirt@zte.com.cn
tags:
  - nvd
  - cve.org
epss: 0.00204
epssPercentile: 0.09134
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T18:05:35.918299Z'
ingestedAt: '2026-09-20T10:19:44.905Z'
---

## Overview

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
