Description
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.
Published: 2026-09-20
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account registration bypass
Action: Patch
AI Analysis

Impact

A flaw in ZTE SmartLife allows an attacker to generate new user accounts without verifying ownership of the email address supplied. By using the dynamic authentication parameters that the app creates at runtime, an adversary can invoke the backend endpoint /account/person/signup.serv and register any arbitrary email address. This bypass can lead to spoofed or fraudulent accounts and potentially compromise privacy, integrity, or availability of the service. The weakness is an authorization bypass, identified as CWE-269.

Affected Systems

ZTE SmartLife mobile application (ZTE SmartLife app) is affected. The vendor does not disclose affected firmware or app versions, so any current or past release of the SmartLife app may be vulnerable until a fix is applied.

Risk and Exploitability

The CVSS score of 5.4 places this issue in the low‑to‑moderate range, and the EPSS score is not available. Because the exploit is exercised through a remote backend interface, an attacker can likely reach the vulnerability from any network that can reach the API. The flaw is not listed in CISA KEV and there is no evidence of widespread exploitation, so the immediate risk is limited to misuse of the registration endpoint and potential account abuse. The likely attack vector is remote access to the /account/person/signup.serv route, which is inferred from the description of the exploitation path.

Generated by OpenCVE AI on September 20, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available ZTE patch or update that enforces email ownership verification before account creation.
  • If no patch is available, restrict access to the /account/person/signup.serv endpoint to trusted clients or IP ranges and add an email confirmation step to the registration process.
  • Monitor and log registration API activity, and investigate bulk or suspicious account creation attempts.

Generated by OpenCVE AI on September 20, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte ztesw
Vendors & Products Zte
Zte ztesw

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.
Title A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-09-21T18:10:51.807Z

Reserved: 2026-09-08T02:55:56.712Z

Link: CVE-2026-86552

cve-icon Vulnrichment

Updated: 2026-09-21T18:10:47.218Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T04:17:02.840

Modified: 2026-09-22T19:41:38.447

Link: CVE-2026-86552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:58Z

Weaknesses
  • CWE-269

    Improper Privilege Management