🔐 CVE Alert

CVE-2026-86552

MEDIUM 4.3

A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.

CWE CWE-269
Vendor zte
Product ztesw
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for zte ztesw

Be the first to know when new medium vulnerabilities affecting zte ztesw are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

ZTE / ZTESW
ZTE_SL_V2.8.2_ABROAD and prior versions

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.zte.com.cn: https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982102946

Credits

Mina Nageh Salama Zekry