Impact
This vulnerability allows an attacker to read unencrypted credentials stored in the device firmware, giving them access to TLS transmission keys. The exposed credentials can be used to decrypt network traffic or to impersonate the device in secure communications, potentially leading to data interception or man‑in‑the‑middle attacks. The weakness is a classic example of insecure key storage, documented as CWE‑321.
Affected Systems
The affected device is the ZTE F689 series. No specific firmware versions are listed, so all devices running the current firmware release may be vulnerable. Administrators should check for firmware revisions and identify whether the device stores TLS credentials unencryption.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is that an attacker must obtain the firmware or access the device’s internal storage, which implies local or privileged access, though the exact approach is not specified in the description.
OpenCVE Enrichment