中兴 SmartLife 应用程序中存在硬编码密钥的问题。用于解密账户服务器信息的密钥以明文形式存储在代码中。一旦获取该密钥,服务器信息即可被解密,从而被暴露出来。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-86553 | 8.8 HIGH | A password reset vulnerability in ZTE SmartLife APP |
| CVE-2026-86552 | 5.4 MEDIUM | A vulnerability that skips email ownership verification for account registration in ZTE Sm |
| CVE-2026-86554 | 4.3 MEDIUM | Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP |
| CVE-2026-86551 | 3.3 LOW | Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX74 |
No comments yet