Impact
The vulnerability allows an attacker to read unencrypted data embedded in the device firmware and extract credentials that are used for the integrity‑check function of a particular application. This exposure permits the disclosure of sensitive authentication material, which could in turn enable the attacker to spoof integrity verification processes or bypass related security controls. The weakness aligns with CWE‑321, indicating improper handling of cryptographic keys.
Affected Systems
ZTE F689 devices are affected. No specific firmware version information is provided by the CNA; all deployed units of the F689 model should be considered potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk level. EPSS data is not available, so the likelihood of exploitation cannot be quantified from public probability data, and the vulnerability is not listed in CISA KEV. The attack is likely feasible for an adversary who can access the device firmware—either through local physical access or via a remote interface that exposes the firmware contents—though the exact attack vector is not specified in the available data. Once the credentials are obtained, the attacker could misuse them to compromise device integrity or other components that rely on the same authentication mechanism.
OpenCVE Enrichment