2026-09-20 7:55CVE-2026-86554zte
PUBLISHED5.2CWE-269

Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

Problem type

Affected products

ZTE

SmartLife

ZTE_SL_V2.8.2_ABROAD and prior versions - AFFECTED

References

GitHub Security Advisories

GHSA-72pp-r64r-349h

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters...

https://github.com/advisories/GHSA-72pp-r64r-349h

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-86554
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-86554",
    "assignerOrgId": "6786b568-6808-4982-b61f-398b0d9679eb",
    "assignerShortName": "zte",
    "dateUpdated": "2026-09-20T09:17:21.674Z",
    "dateReserved": "2026-09-08T02:55:56.712Z",
    "datePublished": "2026-09-20T07:55:08.842Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "6786b568-6808-4982-b61f-398b0d9679eb",
        "shortName": "zte",
        "dateUpdated": "2026-09-20T09:17:21.674Z"
      },
      "title": "Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP",
      "descriptions": [
        {
          "lang": "en",
          "value": "SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "ZTE",
          "product": "SmartLife",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "ZTE_SL_V2.8.2_ABROAD and prior versions",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "# CWE-269 Improper Privilege Management",
              "cweId": "CWE-269",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2171542593031840113"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-115",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-115 Authentication Bypass"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Mina Nageh Salama Zekry",
          "type": "finder"
        }
      ]
    }
  }
}