Junglewise Threat Intelligence

CVE-2026-86552: ZTE SmartLife authentication bypass in account registration

CVE-2026-86552 · Severity: medium · CVSS 5.4 · Published 2026-09-20

Technologies: Zte SmartLife. Vendors: Zte.

Executive brief

The ZTE SmartLife app is a mobile application for managing smart home devices. An attacker with access to the app's authentication credentials can register arbitrary email addresses without verification, potentially gaining unauthorized account access and control over associated smart home systems or user data.

Technical details

The SmartLife app generates authentication parameters dynamically at runtime, and these credentials can be extracted or reused by an attacker. The backend endpoint /account/person/signup.serv accepts account registration requests without validating email ownership, allowing account takeover and unauthorized access when paired with the compromised app credentials.

Affected products

  • ZTE SmartLife

Timeline

  • 2026-09-20: disclosed

References

Related threats