Executive brief
The ZTE SmartLife app is a mobile application for managing smart home devices. An attacker with access to the app's authentication credentials can register arbitrary email addresses without verification, potentially gaining unauthorized account access and control over associated smart home systems or user data.
Technical details
The SmartLife app generates authentication parameters dynamically at runtime, and these credentials can be extracted or reused by an attacker. The backend endpoint /account/person/signup.serv accepts account registration requests without validating email ownership, allowing account takeover and unauthorized access when paired with the compromised app credentials.
Affected products
- ZTE SmartLife
Timeline
- 2026-09-20: disclosed