Impact
SmartLife application creates new authentication parameters when it starts. An attacker who obtains these credentials can use the /account/person/signup.serv endpoint to create a new user account with any chosen e‑mail address. The registration process does not verify that the e‑mail address actually belongs to the user. This vulnerability allows an attacker to generate accounts without proof of ownership, potentially enabling impersonation or fraudulent activity.
Affected Systems
ZTE SmartLife application is affected. Specific version details are not disclosed by the vendor, so any current or past release of the SmartLife app may be vulnerable until this issue is remediated.
Risk and Exploitability
With a CVSS score of 4.3, the threat is considered low to moderate. The EPSS score is not available. Because the flaw is reached through a remote backend interface, an attacker can exploit it from any network that can reach the API. The vulnerability is not known to be exploited in the field and is not listed in the CISA KEV catalog, so the current risk is limited to misuse of the registration endpoint and subsequent potential for account abuse.
OpenCVE Enrichment