Junglewise Threat Intelligence

CVE-2026-40436: ZTE ZXEDM iEMS password reset vulnerability in cloud EMS portal

CVE-2026-40436 · Severity: high · CVSS 7.1 · Published 2026-04-13

Vendors: Zte.

Executive brief

ZTE ZXEDM iEMS, a management system for cloud-based Element Management Systems (EMS), contains a security flaw that allows unauthorized access to user data. Attackers can exploit this to view a complete list of system users and subsequently reset their passwords. This could lead to a total takeover of user accounts, allowing unauthorized individuals to perform administrative operations and disrupt critical network management services.

Technical details

A vulnerability in the ZTE ZXEDM iEMS cloud portal stems from improper access control on the user list acquisition interface. A network-based attacker can exploit this lack of authorization to retrieve sensitive information for all registered users. With this information, the attacker can trigger a password reset for any account. While the vendor's CVSS vector suggests some complexity (AC:H) and user interaction (UI:R) may be involved, the primary root cause is a failure to restrict access to administrative user-management functions. Successful exploitation allows for unauthorized operations and full account compromise.

Affected products

  • ZTE ZXEDM iEMS 16.25.42.04

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References