Junglewise Threat Intelligence

CVE-2026-86554: ZTE SmartLife app account enumeration via exposed credentials

CVE-2026-86554 · Severity: medium · CVSS 4.3 · Published 2026-09-20

Technologies: Zte SmartLife. Vendors: Zte.

Executive brief

The ZTE SmartLife mobile app dynamically generates authentication credentials at runtime without adequate protection, allowing attackers to use these credentials to query the backend system. An attacker can determine whether specific email addresses are registered as SmartLife accounts and retrieve associated account IDs, enabling targeted social engineering or credential stuffing attacks.

Technical details

The vulnerability stems from the SmartLife app's runtime generation of authentication parameters without proper obfuscation or server-side validation. Attackers can intercept or reverse-engineer these authentication credentials, then invoke the /account/verify.serv backend endpoint to enumerate valid email addresses and retrieve backend account IDs. This is an information disclosure vulnerability requiring network access and knowledge of the authentication scheme.

Affected products

  • ZTE SmartLife

Timeline

  • 2026-09-20: disclosed

References

Related threats