🔐 CVE Alert

CVE-2026-86554

MEDIUM 4.3

Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

CWE CWE-269
Vendor zte
Product smartlife
Published Sep 20, 2026
Last Updated Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for zte smartlife

Be the first to know when new medium vulnerabilities affecting zte smartlife are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

ZTE / SmartLife
ZTE_SL_V2.8.2_ABROAD and prior versions

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.zte.com.cn: https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2171542593031840113

Credits

Mina Nageh Salama Zekry