{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-49000",
        "assignerOrgId": "6786b568-6808-4982-b61f-398b0d9679eb",
        "state": "PUBLISHED",
        "assignerShortName": "zte",
        "dateReserved": "2026-05-27T01:01:53.326Z",
        "datePublished": "2026-05-27T03:38:48.971Z",
        "dateUpdated": "2026-05-28T03:36:43.477Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "6786b568-6808-4982-b61f-398b0d9679eb",
                "shortName": "zte",
                "dateUpdated": "2026-05-28T03:36:43.477Z"
            },
            "title": "Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-310",
                            "description": "CWE-310 Cryptographic Issues",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-97",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-97 Cryptanalysis"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "ZTE",
                    "product": "ZXUniPOS NDS-LTE",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01)"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.</p><p></p><p><br></p><br>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3711746568357343394"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "LOW",
                        "baseSeverity": "HIGH",
                        "baseScore": 7,
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Venom Nguyen from VNPT-NET",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-05-27T18:01:13.138498Z",
                                "id": "CVE-2026-49000",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-05-27T18:01:20.640Z"
                }
            }
        ]
    }
}