Impact
A flaw in ZTE SmartLife allows an attacker to generate new user accounts without verifying ownership of the email address supplied. By using the dynamic authentication parameters that the app creates at runtime, an adversary can invoke the backend endpoint /account/person/signup.serv and register any arbitrary email address. This bypass can lead to spoofed or fraudulent accounts and potentially compromise privacy, integrity, or availability of the service. The weakness is an authorization bypass, identified as CWE-269.
Affected Systems
ZTE SmartLife mobile application (ZTE SmartLife app) is affected. The vendor does not disclose affected firmware or app versions, so any current or past release of the SmartLife app may be vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 5.4 places this issue in the low‑to‑moderate range, and the EPSS score is not available. Because the exploit is exercised through a remote backend interface, an attacker can likely reach the vulnerability from any network that can reach the API. The flaw is not listed in CISA KEV and there is no evidence of widespread exploitation, so the immediate risk is limited to misuse of the registration endpoint and potential account abuse. The likely attack vector is remote access to the /account/person/signup.serv route, which is inferred from the description of the exploitation path.
OpenCVE Enrichment