CVE-2026-86554: Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to obtain SmartLife application authentication parameters generated by the app at runtime. The provided information does not state that a target user's credentials or interaction are required.
What information can an attacker obtain?
The backend interface can be used to determine whether a target email address is registered for a SmartLife account. For registered accounts, it can also return the real backend account ID.
How can I tell whether an account may have been exposed?
The available information does not provide logs, indicators, or detection methods. The described exposure concerns account-registration status and backend account IDs queried through the /account/verify.serv interface.