SmartLife 应用会在其运行时进程中动态生成全新的 SmartLife 应用认证参数。利用获取到的这些认证参数,攻击者可以直接调用后端接口 ,从而获取与已注册邮箱相对应的真实账户 ID。通过伪装应用认证信息并配合目标账户 ID,攻击者即可重置该目标账户的密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86555 | 6.2 MEDIUM | Hardcoded Key Vulnerability in ZTE SmartLife APP |
| CVE-2026-86552 | 5.4 MEDIUM | A vulnerability that skips email ownership verification for account registration in ZTE Sm |
| CVE-2026-86554 | 4.3 MEDIUM | Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP |
| CVE-2026-86551 | 3.3 LOW | Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX74 |
No comments yet