SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 20 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved. | |
| Title | Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-09-20T09:17:21.674Z
Reserved: 2026-09-08T02:55:56.712Z
Link: CVE-2026-86554
No data.
Status : Received
Published: 2026-09-20T08:16:50.950
Modified: 2026-09-20T10:16:52.700
Link: CVE-2026-86554
No data.
OpenCVE Enrichment
Updated: 2026-09-20T09:30:18Z
Weaknesses