Junglewise Threat Intelligence

CVE-2026-86553: ZTE SmartLife app authentication bypass in account verification

CVE-2026-86553 · Severity: high · CVSS 8.8 · Published 2026-09-20

Technologies: Zte SmartLife. Vendors: Zte.

Executive brief

ZTE's SmartLife app, used to manage smart home devices, generates authentication parameters that can be intercepted by an attacker. An attacker can use these parameters to discover registered email addresses and reset account passwords without proper authorization, potentially giving an attacker full control over connected smart home systems.

Technical details

The SmartLife application generates authentication parameters at runtime that are insufficiently protected, allowing an attacker to extract them. By replaying these parameters against the /account/verify.serv backend endpoint, an attacker can enumerate account IDs by email address; combined with spoofed authentication, this enables unauthorized password reset without knowledge of the original credentials.

Affected products

  • ZTE SmartLife

Timeline

  • 2026-09-20: disclosed

References

Related threats