What is CVE-2026-8029?
An SQL injection vulnerability has been found in the ZTE Smart Life app. Attackers can use UNION SELECT statements to query sensitive data from the feedback.db database, including user accounts and phone numbers. Users are advised to immediately update the app to the latest version.
Azərbaycanca: ZTE Smart Life tətbiqində SQL injection zəifliyi aşkar edilib. Hücumçular UNION SELECT əməliyyatı vasitəsilə feedback.db bazasından istifadəçi hesabları və telefon nömrələri kimi həssas məlumatları oğurlaya bilər. İstifadəçilərə təcili olaraq tətbiqi son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
What type of threat does CVE-2026-8029 pose in the ZTE Smart Life app?
This is an SQL injection vulnerability. Attackers can use a UNION SELECT operation to steal sensitive data from the feedback.db database, including user accounts and phone numbers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.