Executive brief
ZTE's SmartLife app, used to manage smart home devices, generates authentication parameters that can be intercepted by an attacker. An attacker can use these parameters to discover registered email addresses and reset account passwords without proper authorization, potentially giving an attacker full control over connected smart home systems.
Technical details
The SmartLife application generates authentication parameters at runtime that are insufficiently protected, allowing an attacker to extract them. By replaying these parameters against the /account/verify.serv backend endpoint, an attacker can enumerate account IDs by email address; combined with spoofed authentication, this enables unauthorized password reset without knowledge of the original credentials.
Affected products
- ZTE SmartLife
Timeline
- 2026-09-20: disclosed