SmartLife vulnerabilities
CVEs whose affected-version data names the SmartLife package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-86555Medium· 6.2The ZTE SmartLife application has a hardcoded key
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
CVE-2026-86554Medium· 4.3SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interf…
CVE-2026-86553High· 8.8SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface…
CVE-2026-86552Medium· 5.4PoCSmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitr…