← back
CVE-2026-8029lowCWE-89

SQL Injection Vulnerability in ZTE SmartLife App

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.9epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected products
ZTE · SmartLife