CVE-2026-40436

7.1

ZTE · ZXEDM iEMS

A privilege management flaw in the ZTE ZXEDM iEMS user list interface allows authenticated users to read user information and perform unauthorized password resets.

Executive summary

A critical privilege management vulnerability in the ZTE ZXEDM iEMS platform allows authenticated attackers to compromise user accounts via unauthorized password resets.

Vulnerability

This vulnerability involves improper privilege management (CWE-269) where the cloud EMS portal fails to restrict access to user list acquisition functions. An authenticated user can leverage this to enumerate sensitive user information and subsequently reset passwords for targeted accounts.

Business impact

The ability for an authenticated user to perform unauthorized password resets poses a severe risk to organizational data integrity and system security. With a CVSS score of 7.1, this high-severity flaw enables attackers to escalate privileges or hijack administrative sessions, potentially leading to full system compromise and significant operational disruption.

Remediation

Immediate Action: Review the official ZTE security bulletin and apply the provided security updates or configuration changes recommended by the vendor.

Proactive Monitoring: Audit system logs for unusual access patterns directed at user list interfaces or frequent password reset requests from non-administrative accounts.

Compensating Controls: Implement strict access control lists on the management portal and restrict access to the affected interface to authorized network segments only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized account manipulation and privilege escalation, organizations utilizing the affected version of ZTE ZXEDM iEMS must prioritize this update. Administrators should restrict access to the management portal while awaiting vendor patches to minimize the attack surface for potential malicious actors.

More ZTE CVEs

Sources

Originally found and disclosed by Wenwei Shi, per the CVE Program record.