CVE-2026-49007
Received Received - Intake

Hard-Coded Credentials in ZTE Device Firmware

Vulnerability report for CVE-2026-49007, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: ZTE Corporation

Description

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to access unencrypted information in the device firmware to obtain the initial login credentials for the device's web interface.

Impact Analysis

An attacker could gain unauthorized access to the device's web interface using the stolen credentials, potentially leading to further compromise of the device or network.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR or HIPAA by exposing sensitive login credentials, potentially leading to unauthorized access and data breaches.

Mitigation Strategies

Update device firmware to the latest secure version to prevent exposure of unencrypted credentials. Disable remote access to the web interface if not required. Monitor network traffic for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49007. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart