ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification

ZTE has addressed four vulnerabilities in its SmartLife mobile application following the discovery of critical weaknesses that allowed attackers to enumerate accounts, retrieve account identifiers, reset passwords, and take over user accounts. The most severe vulnerability, labeled as CVE-2026-86553, was assigned a CVSS score of 8.8 and affected ZTE SmartLife versions 2.8.2 and earlier. This […]

This article has been indexed from Cyber Security News

Read the original article: