CVE-2026-8029
Received Received - Intake

SQL Injection in ZTE Smart Life App

Vulnerability report for CVE-2026-8029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: ZTE Corporation

Description

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zte smart_life *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ZTE Smart Life app has an SQL injection flaw that lets attackers use UNION SELECT statements to access sensitive data in the feedback.db database. This includes user accounts, phone numbers, feedback content, and local debug log paths, allowing theft of local privacy data.

Detection Guidance

Detecting SQL injection vulnerabilities in the ZTE Smart Life app requires analyzing the app's database interactions. Check for unusual UNION SELECT queries in the app's network traffic or logs. Inspect feedback.db for unexpected data exposure. No specific commands are provided in the context.

Impact Analysis

Attackers could steal your personal information like account details, phone numbers, feedback content, and debug logs from your device. This could lead to privacy breaches or identity theft if sensitive data is exposed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data such as accounts, phone numbers, and feedback content, which may violate GDPR and HIPAA compliance requirements for data protection and privacy.

Mitigation Strategies

Immediately uninstall or disable the ZTE Smart Life app from all affected devices to prevent potential exploitation of the SQL injection vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart