CVE-2026-49000
Received Received - Intake
Insecure Password Scheme in ZTE Product

Publication date: 2026-05-27

Last updated on: 2026-05-27

Assigner: ZTE Corporation

Description
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-27
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-310 Cryptographic Issues
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves an insecure password scheme caused by improper selection of encryption algorithms, inadequate key management, or flawed code implementation. Examples include the use of hard-coded keys or weak encryption algorithms, which can lead to data leakage or tampering.

Impact Analysis

The vulnerability can lead to unauthorized data leakage or tampering due to weak encryption or poor key management. This may compromise the confidentiality, integrity, and availability of sensitive information.

Compliance Impact

This vulnerability involves insecure password schemes due to weak encryption algorithms, poor key management, or flawed implementation, which can lead to data leakage or tampering.

Such weaknesses can impact compliance with standards and regulations like GDPR and HIPAA, which require adequate protection of sensitive data to prevent unauthorized access and ensure data integrity.

Failure to properly secure passwords and encryption mechanisms may result in violations of these regulations, potentially leading to legal and financial consequences.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart