Description
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.
Published: 2026-08-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to read unencrypted data embedded in the device firmware and extract credentials that are used for the integrity‑check function of a particular application. This exposure permits the disclosure of sensitive authentication material, which could in turn enable the attacker to spoof integrity verification processes or bypass related security controls. The weakness aligns with CWE‑321, indicating improper handling of cryptographic keys.

Affected Systems

ZTE F689 devices are affected. No specific firmware version information is provided by the CNA; all deployed units of the F689 model should be considered potentially vulnerable unless a patch has been applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high risk level. EPSS data is not available, so the likelihood of exploitation cannot be quantified from public probability data, and the vulnerability is not listed in CISA KEV. The attack is likely feasible for an adversary who can access the device firmware—either through local physical access or via a remote interface that exposes the firmware contents—though the exact attack vector is not specified in the available data. Once the credentials are obtained, the attacker could misuse them to compromise device integrity or other components that rely on the same authentication mechanism.

Generated by OpenCVE AI on August 7, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to a version in which the integrity‑check credentials are stored securely (e.g., encrypted or protected by a cryptographic key manager).
  • Limit or disable any interfaces that allow firmware reading or downloading to prevent attackers from accessing unencrypted data.
  • If an update is not immediately available, isolate the device from untrusted networks and enforce strict physical access controls to reduce the risk of credential acquisition.

Generated by OpenCVE AI on August 7, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.
Title Integrity‑check credential leakage vulnerability in an application function of ZTE F689 product
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-08-07T08:03:49.107Z

Reserved: 2026-05-27T01:01:53.327Z

Link: CVE-2026-49008

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:30:11Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key