Critical ZTE SmartLife Flaws Let Attackers Hijack Accounts
Key Takeaways ZTE has remediated four critical vulnerabilities in its SmartLife mobile application. The most severe flaw, CVE-2026-86553, carried a CVSS score of 8.8 and allowed for unauthenticated...
Key Takeaways
- ZTE has remediated four critical vulnerabilities in its SmartLife mobile application.
- The most severe flaw, CVE-2026-86553, carried a CVSS score of 8.8 and allowed for unauthenticated account takeovers.
- Affected versions include ZTE SmartLife 2.8.2 and earlier.
- The vulnerabilities were identified by security researcher Mina Nageh Salama and have since been patched by ZTE.
- Users are advised to update their SmartLife app and change their passwords.
ZTE has released patches for four significant security vulnerabilities discovered in its SmartLife mobile application. These flaws, if exploited, could have allowed malicious actors to enumerate user accounts, retrieve sensitive identifiers, reset passwords without authorization, and ultimately hijack user accounts.
Table Of Content
Critical Account Takeover Flaw Identified
The most severe of the vulnerabilities, tracked as CVE-2026-86553, received a high CVSS score of 8.8. This critical flaw impacted ZTE SmartLife versions 2.8.2 and all prior iterations of the application. The vulnerability stemmed from an insecure password reset mechanism.
Specifically, the SmartLife application’s backend permitted a password reset request to complete successfully by merely providing a target account ID and a new password. Crucially, this process lacked any server-side verification, bypassing the necessity for the requester to prove ownership of the account or to validate through a reset-code mechanism.
A standard password reset protocol typically involves sending a unique code to the account owner for validation, or requiring another form of strong user authentication before a new password can be set. However, the SmartLife backend accepted password changes based solely on an account identifier and a new password, creating a direct path for account compromise, particularly when combined with an email enumeration vulnerability.
As detailed in the CVE description, attackers could leverage legitimate SmartLife application authentication parameters to query the /account/verify.serv backend interface. This allowed them to check if a specific email address was registered with the service. If a valid account email was supplied, the API would also disclose the associated backend account ID. With this ID, and potentially spoofed authentication data, an attacker could then proceed to reset the victim’s password successfully.
The researcher who uncovered these issues verified the flaw using accounts they controlled. The successful execution of a password change using the new credentials confirmed that the vulnerability directly enabled unauthorized access to the SmartLife service.
Detailed Breakdown of ZTE SmartLife Vulnerabilities
The flaws were uncovered by security researcher Mina Nageh Salama during a broader investigation into the SmartLife ecosystem, which also included an examination of ZTE router firmware (models H188A and H288A). This research ultimately led to a focused analysis of the cloud account services underpinning the official ZTE SmartLife Android application.
In total, the coordinated disclosure process resulted in four distinct CVEs, and ZTE has confirmed that all identified issues have been fully remediated.
| CVE | Issue | CVSS | Impact |
|---|---|---|---|
| CVE-2026-86552 | Email verification bypass | 5.4 | Fake account registration |
| CVE-2026-86553 | Password reset flaw | 8.8 | Account takeover |
| CVE-2026-86554 | Email/account ID disclosure | 4.3 | Account enumeration |
| CVE-2026-86555 | Hardcoded mobile app key | 6.2 | Server information exposure |
Beyond the critical password reset flaw, CVE-2026-86554, an email enumeration vulnerability, allowed attackers to distinguish between registered and unregistered SmartLife email addresses. When a registered email was provided, the backend would reveal the account’s actual backend identifier, significantly increasing the exploitability of the password reset vulnerability.
Another issue, CVE-2026-86555, involved a hardcoded key embedded within the SmartLife application. This key could be extracted, potentially allowing an attacker to decrypt sensitive account-server information.
The implications of these vulnerabilities are substantial. A core architectural weakness was the backend system’s over-reliance on application-level authentication for critical account actions. While such authentication can indicate a request originates from an authorized application context, it is insufficient as a sole replacement for robust proof that the requester controls the specific account being modified.
A compromised SmartLife account could expose users to significant risks within their connected home environments, as the application manages numerous home and device configurations. Consequently, account compromise could lead to repercussions far beyond simple profile access, potentially impacting the security and privacy of an entire smart home ecosystem.
ZTE has confirmed that all reported issues have been fully patched, with advisories released on September 20, 2026.
What You Should Do
- Update Your App: Immediately update the ZTE SmartLife application to the latest version available in official app stores.
- Change Passwords: It is highly recommended to change your SmartLife account password, especially if you have reused it across other online services.
- Review Connected Devices: Regularly review all devices connected to your SmartLife account and verify the list of authorized shared-home members to ensure no unauthorized access.
- Enable Multi-Factor Authentication (MFA): If SmartLife offers MFA, enable it without delay for an additional layer of security.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.