SmartLife App 在运行时动态生成全新的 SmartLife 应用认证参数。攻击者一旦获取了 SmartLife 应用的认证凭据,就可以通过后端接口 /account/person/signup.serv 使用任意电子邮件地址直接完成注册,而在注册前不会验证该邮箱的所有权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86553 | 8.8 HIGH | A password reset vulnerability in ZTE SmartLife APP |
| CVE-2026-86555 | 6.2 MEDIUM | Hardcoded Key Vulnerability in ZTE SmartLife APP |
| CVE-2026-86554 | 4.3 MEDIUM | Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP |
| CVE-2026-86551 | 3.3 LOW | Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX74 |
No comments yet