Executive brief
ZTE ZXEDM iEMS, a management system for cloud-based Element Management Systems (EMS), contains a security flaw that allows unauthorized access to user data. Attackers can exploit this to view a complete list of system users and subsequently reset their passwords. This could lead to a total takeover of user accounts, allowing unauthorized individuals to perform administrative operations and disrupt critical network management services.
Technical details
A vulnerability in the ZTE ZXEDM iEMS cloud portal stems from improper access control on the user list acquisition interface. A network-based attacker can exploit this lack of authorization to retrieve sensitive information for all registered users. With this information, the attacker can trigger a password reset for any account. While the vendor's CVSS vector suggests some complexity (AC:H) and user interaction (UI:R) may be involved, the primary root cause is a failure to restrict access to administrative user-management functions. Successful exploitation allows for unauthorized operations and full account compromise.
Affected products
- ZTE ZXEDM iEMS 16.25.42.04
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory