important · Mobile
Knowing a ZTE SmartLife email address is enough for demonstrated account takeover.
Affects
ZTE SmartLife Android and iOS clients and their internet-facing cloud account backend for ZTE smart-home devices.
Recoverable client secrets enable signed requests, an oracle returns the backend account ID, and the reset endpoint accepts a new password without a verified reset transaction. The researcher reproduced password replacement and login against controlled accounts. A fix is published, but it was not reviewed for this brief, so this cannot lead.
Detail and 4 sources
Sources
ResearchZTE Smarthome TakeOverResearchTechGeeks Field Notes - Networking, Security, AI, Linux and PisoWiFiCode / PoCGitHub - minanagehsalalma/zte-smartlife-app-pwned: ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555. · GitHubVendorZTE Corporation