Description
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to read unencrypted credentials stored in the device firmware, giving them access to TLS transmission keys. The exposed credentials can be used to decrypt network traffic or to impersonate the device in secure communications, potentially leading to data interception or man‑in‑the‑middle attacks. The weakness is a classic example of insecure key storage, documented as CWE‑321.

Affected Systems

The affected device is the ZTE F689 series. No specific firmware versions are listed, so all devices running the current firmware release may be vulnerable. Administrators should check for firmware revisions and identify whether the device stores TLS credentials unencryption.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. An EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is that an attacker must obtain the firmware or access the device’s internal storage, which implies local or privileged access, though the exact approach is not specified in the description.

Generated by OpenCVE AI on August 7, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from ZTE that secures TLS credentials in encrypted form
  • Immediately change any default or weak device credentials and reconfigure TLS certificates
  • Disable or restrict firmware extraction and remote retrieval mechanisms to prevent unauthorized access
  • Monitor device logs for unusual firmware access attempts and investigate any anomalies

Generated by OpenCVE AI on August 7, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte f689
Vendors & Products Zte
Zte f689

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title TLS credential leakage vulnerability in ZTE F689 product

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-08-07T15:24:46.283Z

Reserved: 2026-05-27T01:01:53.327Z

Link: CVE-2026-49006

cve-icon Vulnrichment

Updated: 2026-08-07T15:24:39.131Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T08:16:46.323

Modified: 2026-08-26T16:55:49.920

Link: CVE-2026-49006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:26Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key