CVE-2026-86555

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

  • Published Sep 20, 2026
  • CVSS 6.2 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-86555 at the National Vulnerability Database