Impact
The ZTE SmartLife application contains a hardcoded plaintext key that is used to decrypt account server information. When this key is extracted, the application can successfully decrypt sensitive server data, thereby exposing the information. This flaw is a classic example of hard‑coded secret misuse (CWE‑798).
Affected Systems
The vulnerability affects the ZTE SmartLife application. Version information is not provided in the advisory, so all releases that include the hardcoded key are potentially impacted.
Risk and Exploitability
The severity is reflected in a CVSS score of 6.2, indicating a moderate threat level. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The key can be extracted via reverse engineering or static analysis of the application binary, so the attack vector is likely local or through a device that has access to the app’s executable. Once the key is obtained, an adversary can decrypt account server details, leading to unauthorized disclosure of sensitive data.
OpenCVE Enrichment