Description
The root password hash of the device can be obtained through unencrypted information in the firmware.
Published: 2026-08-07
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in ZTE F689 firmware allows an attacker to extract the root password hash from unencrypted information embedded within the device software. The exposed hash is a credential that, if recovered, could enable full administrative control over the device. This vulnerability represents a pure information‐disclosure flaw and does not involve active code execution or privilege escalation beyond the acquisition of the hash.

Affected Systems

All ZTE F689 devices are potentially impacted. No specific firmware release dates or version numbers are listed in the advisory, so any firmware built with the current product line should be considered at risk until the vendor publishes a covered update.

Risk and Exploitability

The CVSS score of 2.4 indicates a low overall risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires that an adversary obtain the firmware image, which might be possible through local access to the device or via any exposed firmware download interface. Based on the description, it is inferred that once the firmware is captured, an attacker would need to use offline techniques to crack the hash; therefore, the primary control vector is the disclosure of the credential rather than an immediate remote exploit.

Generated by OpenCVE AI on August 7, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by ZTE that fixes the CWE‑916 flaw.
  • If a patch is not available, restrict all interfaces that permit firmware download or upload to trusted administrators only, and disable any unnecessary network services that may expose firmware data.
  • Verify the authenticity of the firmware image by comparing its checksum to the values published by the vendor and monitor device logs for any unauthorized firmware transfer attempts.

Generated by OpenCVE AI on August 7, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte f689
Vendors & Products Zte
Zte f689

Fri, 07 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description The root password hash of the device can be obtained through unencrypted information in the firmware.
Title Root password hash exposure vulnerability in ZTE F689 product
Weaknesses CWE-916
References
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-08-07T15:31:40.271Z

Reserved: 2026-05-27T01:01:53.327Z

Link: CVE-2026-49005

cve-icon Vulnrichment

Updated: 2026-08-07T15:31:35.951Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T05:17:02.083

Modified: 2026-08-26T16:55:49.920

Link: CVE-2026-49005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:58:28Z

Weaknesses
  • CWE-916

    Use of Password Hash With Insufficient Computational Effort