# CVE-2026-49000

## Summary

- **CVE ID:** CVE-2026-49000
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L)
- **CWE:** CWE-310
- **Published:** May 27, 2026
- **Last Modified:** May 28, 2026

## Description

An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

## Affected Products

- ZTE — ZXUniPOS NDS-LTE (V24.30.40CP02 and earlier versions)
- ZTE — ZXUniPOS NDS-LTE (V24.40.40 and earlier versions)
- ZTE — ZXUniPOS NDS-LTE (Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01))

## References

- [CNA](https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3711746568357343394)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._