CVE-2026-86554 PUBLISHED

Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP

Assigner: zte
Reserved: 08.09.2026 Published: 20.09.2026 Updated: 20.09.2026

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor ZTE
Product ZTESW
Versions Default: unaffected
  • Version ZTE_SL_V2.8.2_ABROAD and prior versions is affected

Credits

  • Mina Nageh Salama Zekry finder

References

Problem Types

  • # CWE-269 Improper Privilege Management CWE

Impacts

  • CAPEC-115 Authentication Bypass