Back to feed

ZTE patches SmartLife flaws enabling account takeover via password reset

1 min
ZTE patches SmartLife flaws enabling account takeover via password reset

This digest was compiled by AI from multiple sources — links to the originals are below.

ZTE has patched four vulnerabilities in its SmartLife platform that allowed attackers to reset user passwords without verification and take over accounts. The most severe flaw, CVE-2026-86553, rated 8.8, enabled password resets without proof of ownership. Users must update the SmartLife app to protect their devices.

Key Facts

  • Security researcher Mina Nageh Salama disclosed four critical vulnerabilities in ZTE's SmartLife platform.
  • The most severe vulnerability, CVE-2026-86553, has a CVSS score of 8.8 and allows password resets without verification.
  • ZTE has confirmed the flaws, assigned CVE identifiers, and released patches.
  • The attack chain uses cryptographic material from CVE-2026-86555 to decrypt data and forge authorized requests.
  • Users are urged to update the SmartLife app, use strong passwords, and review connected device configurations.

Vulnerability Chain

The attack chain begins with CVE-2026-86555, which exposes cryptographic material embedded in the SmartLife application. Attackers use this material to decrypt sensitive data and construct requests that the SmartLife backend recognizes as authorized. CVE-2026-86554 and CVE-2026-86552 then aid in identifying existing accounts and allow for account squatting. The most severe flaw, CVE-2026-86553, enables password resets without any verification code or proof of account ownership.

ZTE Response

ZTE has confirmed the vulnerabilities, assigned CVE identifiers, and released patches for the SmartLife platform. The company urges users to apply the security updates to protect their devices. Users are also advised to use strong, unique passwords and review their connected device configurations for unauthorized changes.

2 sources

Time · lag behind first