CVE-2026-8029 - CERT CVE
ID CVE-2026-8029
Sažetak The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.
Reference
CVSS
Base: 3.9
Impact: 3.6
Exploitability:0.3
Pristup
VektorSloženostAutentikacija
PHYSICAL HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Zadnje važnije ažuriranje 05-08-2026 - 14:17
Objavljeno 05-08-2026 - 09:18