SQL Injection Vulnerability in ZTE SmartLife App
Summary
| CVE | CVE-2026-8029 |
|---|---|
| State | PUBLISHED |
| Assigner | zte |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-05 09:18:16 UTC |
| Updated | 2026-08-05 14:17:15 UTC |
| Description | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data. |
Risk And Classification
Primary CVSS: v3.1 3.9 LOW from [email protected]
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.001340000 probability, percentile 0.032830000 (date 2026-08-09)
Problem Types: CWE-89 | CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.9 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 3.9 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
HighPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729 | [email protected] | support.zte.com.cn | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: DHK Dark Horse (en)
There are currently no legacy QID mappings associated with this CVE.