Back Scworld ZTE SmartLife platform vulnerabilities allow account takeover | brief
A chain of vulnerabilities discovered in ZTE's SmartLife platform could allow attackers to take over user accounts by resetting passwords without proper verification. ZTE has confirmed these flaws, assigned CVE identifiers, and released patches, but users must apply the security updates to protect their devices, based on information published by Cyber Insider.
Security researcher Mina Nageh Salama disclosed four critical vulnerabilities in the SmartLife platform, with the most severe, CVE-2026-86553, rated 8.8. This flaw enabled attackers to reset user passwords without any verification code or proof of account ownership. The attack chain involved exploiting cryptographic material embedded in the SmartLife application (CVE-2026-86555) to decrypt sensitive data, which then allowed an attacker to construct requests that the SmartLife backend recognized as authorized. Further vulnerabilities (CVE-2026-86554 and CVE-2026-86552) aided in identifying existing accounts and allowed for account squatting.
While ZTE has patched these issues, users are urged to update their SmartLife application, use strong, unique passwords, and review their connected device configurations for any unauthorized changes.
Source: Cyber Insider
SC Staff September 21, 2026
Laura French September 18, 2026
Collin Hogue-Spears September 18, 2026
Get daily
You can skip this ad in 5 seconds
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
