{"api_version":"1","generated_at":"2026-08-26T12:20:58+00:00","cve":"CVE-2026-8029","urls":{"html":"https://cve.report/CVE-2026-8029","api":"https://cve.report/api/cve/CVE-2026-8029.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-8029","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-8029"},"summary":{"title":"SQL Injection Vulnerability in ZTE SmartLife App","description":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.","state":"PUBLISHED","assigner":"zte","published_at":"2026-08-05 09:18:16","updated_at":"2026-08-05 14:17:15"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')"],"metrics":[{"version":"3.1","source":"psirt@zte.com.cn","type":"Secondary","score":"3.9","severity":"LOW","vector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":3.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"3.9","severity":"LOW","vector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":3.9,"baseSeverity":"LOW","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729","name":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729","refsource":"psirt@zte.com.cn","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-8029","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8029","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ZTE","product":"SmartLife","version":"affected ZTE_SL_V5.0.7and all prior released versions","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"DHK Dark Horse","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"8029","cve":"CVE-2026-8029","epss":"0.001340000","percentile":"0.032830000","score_date":"2026-08-09","updated_at":"2026-08-10 00:07:38"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-8029","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-05T13:03:37.853665Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-05T13:06:32.148Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"SmartLife","vendor":"ZTE","versions":[{"status":"affected","version":"ZTE_SL_V5.0.7and all prior released versions"}]}],"credits":[{"lang":"en","type":"finder","value":"DHK Dark Horse"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data."}],"value":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data."}],"impacts":[{"capecId":"CAPEC-108","descriptions":[{"lang":"en","value":"CAPEC-108 Command Line Execution through SQL Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":3.9,"baseSeverity":"LOW","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-05T08:36:02.928Z","orgId":"6786b568-6808-4982-b61f-398b0d9679eb","shortName":"zte"},"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729"}],"source":{"discovery":"UNKNOWN"},"title":"SQL Injection Vulnerability in ZTE SmartLife App","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"6786b568-6808-4982-b61f-398b0d9679eb","assignerShortName":"zte","cveId":"CVE-2026-8029","datePublished":"2026-08-05T08:36:02.928Z","dateReserved":"2026-05-06T08:50:20.501Z","dateUpdated":"2026-08-05T13:06:32.148Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-05 09:18:16","lastModifiedDate":"2026-08-05 14:17:15","problem_types":["CWE-89","CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')"],"metrics":{"cvssMetricV31":[{"source":"psirt@zte.com.cn","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":3.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-05T13:03:37.853665Z","id":"CVE-2026-8029","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"8029","Ordinal":"1","Title":"SQL Injection Vulnerability in ZTE SmartLife App","CVE":"CVE-2026-8029","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"8029","Ordinal":"1","NoteData":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.","Type":"Description","Title":"SQL Injection Vulnerability in ZTE SmartLife App"}]}}}