SmartLife 应用程序在其运行过程中动态生成全新的 SmartLife 应用认证参数。利用这些获取到的认证参数,攻击者可以直接调用后端接口 来判断目标邮箱地址是否已注册 SmartLife 账户。如果账户存在,还可以获取该账户的真实后端账户 ID。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86553 | 8.8 HIGH | A password reset vulnerability in ZTE SmartLife APP |
| CVE-2026-86555 | 6.2 MEDIUM | Hardcoded Key Vulnerability in ZTE SmartLife APP |
| CVE-2026-86552 | 5.4 MEDIUM | A vulnerability that skips email ownership verification for account registration in ZTE Sm |
| CVE-2026-86551 | 3.3 LOW | Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX74 |
No comments yet