CVE-2026-86552
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Summary
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZTE | SmartLife | ZTE_SL_V2.8.2_ABROAD and prior versions | affected |
Weaknesses
- CWE-269: # CWE-269 Improper Privilege Management
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.