CVE-2026-86553

Summary

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together with the target account ID, the attacker can reset the password of the target account.

Affected Software

VendorProductVersion RangeStatus
ZTESmartLifeZTE_SL_V2.8.2_ABROAD and prior versionsaffected

Weaknesses

  • CWE-269: CWE-269 Improper Privilege Management

References