Description
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
Published: 2026-08-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to retrieve unencrypted initial login credentials from the ZTE F689 device firmware. This direct exposure of administrator credentials enables compromised parties to gain control of the device’s web interface, potentially allowing full administrative access, configuration changes, or exploitation of other component weaknesses. The primary weakness is an insecure default credential storage, identified as CWE‑798.

Affected Systems

The affected system is the ZTE F689 router. No specific firmware version information is provided, so all implementations of this product should be considered vulnerable until a patch or updated firmware is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. EPSS information is not available, so the exact probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access to the device’s firmware or web interface; however, this inference is drawn from the fact that the credentials are obtainable via network communication with the device, and is not explicitly stated in the data.

Generated by OpenCVE AI on August 7, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest ZTE F689 release that removes stored default credentials.
  • If a firmware update is unavailable, disable HTTP access to the web interface and enable HTTPS to protect credential traffic.
  • Change the default administrator password immediately after installing the new firmware and enforce a strong, unique password policy.

Generated by OpenCVE AI on August 7, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte f689
Vendors & Products Zte
Zte f689

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
Title Information leakage vulnerability in ZTE F689 product
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-08-07T15:18:07.082Z

Reserved: 2026-05-27T01:01:53.327Z

Link: CVE-2026-49007

cve-icon Vulnrichment

Updated: 2026-08-07T15:17:19.600Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T08:16:46.457

Modified: 2026-08-26T16:55:49.920

Link: CVE-2026-49007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:21Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials