Description
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte f689
Vendors & Products Zte
Zte f689

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title TLS credential leakage vulnerability in ZTE F689 product

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-08-07T15:24:46.283Z

Reserved: 2026-05-27T01:01:53.327Z

Link: CVE-2026-49006

cve-icon Vulnrichment

Updated: 2026-08-07T15:24:39.131Z

cve-icon NVD

Status : Received

Published: 2026-08-07T08:16:46.323

Modified: 2026-08-07T16:17:25.273

Link: CVE-2026-49006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:26Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key