CVE-2026-86553

8.8

ZTE · ZTESW

A flaw in the SmartLife app allows authenticated users to obtain account IDs and reset passwords by spoofing application authentication parameters during requests to the backend.

Executive summary

A critical vulnerability in the ZTE ZTESW SmartLife application allows an authenticated attacker to perform unauthorized password resets on arbitrary user accounts.

Vulnerability

The vulnerability involves improper privilege management (CWE-269) where an attacker can manipulate authentication parameters generated at runtime. By targeting the /account/verify.serv interface, a low-privileged authenticated attacker can gain full control over other user accounts.

Business impact

The ability for an attacker to reset the passwords of arbitrary users poses a severe risk to data confidentiality and account integrity. With a CVSS score of 8.8, this high-severity flaw could lead to widespread unauthorized access, potential data theft, and significant reputational damage if customer accounts are compromised.

Remediation

Immediate Action: Consult the official ZTE support bulletin at the provided reference link to determine if a patch has been released for your specific deployment. If no patch is available, restrict access to the affected backend interface until vendor guidance is provided.

Proactive Monitoring: Monitor server logs for anomalous traffic directed at the /account/verify.serv endpoint, specifically looking for repeated requests or spikes in password reset activity.

Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block unauthorized requests to the /account/verify.serv endpoint that lack legitimate session context.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security oversight that directly impacts user account security. Organizations utilizing the ZTE SmartLife application must prioritize this issue and maintain constant vigilance for security updates from the vendor. Given the potential for account takeover, disabling the associated service or restricting access to the affected API endpoint is recommended until a definitive patch is applied.

More ZTE CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Mina Nageh Salama Zekry, per the CVE Program record.