ZTE has issued patches for serious flaws in its SmartLife mobile platform after researchers demonstrated how attackers could bypass password resets and hijack user accounts, highlighting ongoing security risks in connected-device ecosystems.
ZTE has patched a set of flaws in its SmartLife mobile platform after researchers showed they could be chained to seize user accounts by bypassing the password-reset process. The issue affects the company’s connected-device ecosystem and centres on weaknesses that allowed an attacker to identify accounts, extract sensitive data from the application and submit reset requests that the backend treated as legitimate.
According to the disclosure reported by Cyber Insider and summarised by SC World, security researcher Mina Nageh Salama found four vulnerabilities in the platform, including the most serious issue, CVE-2026-86553, which carries a CVSS score of 8.8. That flaw allowed password resets without a verification code or any other proof that the requester controlled the account. The attack path reportedly began with cryptographic material embedded in the app itself, listed as CVE-2026-86555, which could be used to decrypt information needed to build a convincing request to ZTE’s servers.
The remaining weaknesses, CVE-2026-86554 and CVE-2026-86552, made the chain more practical by helping an attacker determine whether an account existed and by enabling account squatting. Technical advisories and vulnerability registries describe CVE-2026-86553 as affecting SmartLife 2.8.2 and earlier, with the flaw classed as improper privilege management. The most damaging step was the backend’s acceptance of a reset request tied only to an account identifier and a new password, without a server-side check that would normally confirm account ownership.
ZTE has now issued patches and assigned CVE identifiers, but the protection is only effective if users install the update. Security analysts generally recommend that SmartLife users upgrade the app promptly, choose strong and unique passwords and review connected-device settings for signs of unauthorised changes. In practical terms, the case is a reminder that consumer IoT platforms can fail in basic account security as well as in device management, and that a single authentication weakness can expose an entire connected home.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





