Skip to content
ZTE SmartLife Vulnerabilities Enable Account Takeover

ZTE SmartLife Vulnerabilities Enable Account Takeover

First seen 23 Sep 2026, 23:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 01:23 UTC
  • Four critical vulnerabilities in ZTE SmartLife allow account takeover via password resets.
  • CVE-2026-86553, rated 8.8, enables resets without verification codes.
  • ZTE issued patches on September 3, 2026, but users must apply updates.

Security researcher Mina Nageh Salama disclosed multiple vulnerabilities in ZTE's SmartLife platform that allow attackers to take over user accounts by resetting passwords without verification. The most critical vulnerability, CVE-2026-86553, has a CVSS score of 8.8 and enables password resets without requiring old passwords or verification codes. Other vulnerabilities, including CVE-2026-86555, CVE-2026-86554, and CVE-2026-86552, further facilitate account takeover and email enumeration. ZTE confirmed these flaws, issued CVE identifiers, and released patches on September 3, 2026, but users must apply the updates to secure their devices. The vulnerabilities were discovered while analyzing firmware for ZTE routers and the SmartLife Android application. Users are advised to update their applications and use strong passwords to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-03
ZTE patches vulnerabilities
ZTE released patches for the identified vulnerabilities, urging users to update their SmartLife applications.
Cyber Insider
2026-09-20
CVE identifiers published for vulnerabilities
ZTE confirmed four vulnerabilities in the SmartLife platform, assigning CVE identifiers and releasing patches.
Sploitus
2026-09-20
CVE-2026-86555 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-20
CVE-2026-86553 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-20
CVE-2026-86554 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-21
First public PoC for CVE-2026-86552
The first proof-of-concept for the email ownership verification bypass was made public, demonstrating its exploitability.
Sploitus

More articles in this cluster (3)

Following this threat?

Track ZTE and CVE-2026-86552 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed