ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification
ZTE patched four SmartLife flaws, including an 8.8-severity password reset that enables account takeover.
ZTE patched four SmartLife vulnerabilities affecting versions 2.8.2 and earlier, with advisories issued on September 20, 2026. CVE-2026-86553 (CVSS 8.8) accepts a password reset from an account ID and a new password without proving ownership or checking a reset code. Related flaws allow email enumeration that returns backend account IDs (CVE-2026-86554, CVSS 4.3), fake registration via an email-verification bypass (CVE-2026-86552, CVSS 5.4), and extraction of a hardcoded app key (CVE-2026-86555, CVSS 6.2). Researcher Mina Nageh Salama validated the reset only on accounts they controlled.