CVE-2026-49005
Received Received - Intake

Hard-Coded Root Password Hash in ZTE Device Firmware

Vulnerability report for CVE-2026-49005, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: ZTE Corporation

Description

The root password hash of the device can be obtained through unencrypted information in the firmware.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to retrieve the root password hash from a device's firmware through unencrypted data. The firmware contains sensitive information that should be protected but is exposed in plaintext.

Impact Analysis

An attacker could exploit this to gain unauthorized access to the device by cracking the root password hash. This could lead to full control over the device, data theft, or further network compromise.

Compliance Impact

This vulnerability likely violates data protection requirements under GDPR and HIPAA, as it exposes sensitive authentication data. Organizations may face penalties for failing to secure such information adequately.

Mitigation Strategies

Update the device firmware to the latest version to ensure the root password hash is no longer exposed in unencrypted form. Restrict physical and network access to the device to prevent unauthorized extraction of sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49005. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart