CVE-2026-86555

LOWCVSS 6.2 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-21: 209-21
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid

    Top CVEs w/ public exploits (Sep 21): CVE-2026-88854 Joomla Extension - https://OrdaSoft.com - Unauthenticat... CVE-2026-94036 D-Link DIR-X1860/DIR-X1860Z routerd ubus access... CVE-2026-86555 Hardcoded Key Vulnerability in ZTE SmartLife APP Protect via https://exploitgrid.net

    0003060
    43 followersView on X
  • ExploitGrid@exploitgrid

    💀 Exploits Trending Today CVE-2025-55182 · CVE-2026-81648 · CVE-2023-21554 CVE-2024-31218 · CVE-2025-39682 CVE-2026-86555 — ZTE SmartLife hardcoded key 🤦

    1000045
    43 followersView on X

Explore more