Impact
SmartLife app creates new authentication parameters during execution. An attacker exploiting these parameters can call the backend /account/verify.serv endpoint to discover whether an email address is registered on the service. If the address is valid, the actual backend account identifier is returned, exposing sensitive user information. This vulnerability allows an attacker to gather a list of valid user accounts and obtain account IDs for further exploitation attempts. The weakness is related to improper authorization of verification functionality (CWE-269).
Affected Systems
The vulnerability affects the ZTE SmartLife application provided by ZTE. Specific product details are listed under ZTE:ZTESW, covering all current versions of the SmartLife mobile app where dynamic authentication parameter generation is implemented. No specific version numbers are disclosed in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. The EPSS score is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker sending crafted requests to the backend API from within the mobile app or via a network pass‑through, requiring only knowledge of the authentication parameters. Successful exploitation would enable enumeration of user accounts and disclosure of account identifiers, which could facilitate further targeted attacks such as phishing or credential stuffing.
OpenCVE Enrichment