{"id":"CVE-2026-86554","title":"SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process","summary":"SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interf…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-269"],"vendor":"ZTE","product":"SmartLife","affected":["SmartLife ZTE_SL_V2.8.2_ABROAD and prior versions"],"published":"2026-09-20","updated":"2026-09-20","sourceUpdated":"2026-09-20T10:16:52.700","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86554","references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2171542593031840113","label":"psirt@zte.com.cn"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-20T08:16:57.314Z","epss":0.00196,"epssPercentile":0.09644,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T18:07:24.942498Z"},"slug":"CVE-2026-86554","body":"## Overview\n\nSmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}