❌

Normal view

Received β€” 22 September 2026 ⏭ /r/netsec - Information Security News & Discussion

ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553

Technical write-up for four vulnerabilities I reported in ZTE SmartLife.

The main issue is CVE-2026-86553, a password reset flaw in the SmartLife account backend. The reset endpoint accepted the target accountId and a new password without requiring a reset code, old password, or validated reset transaction.

Another endpoint exposed whether an email was registered and returned the corresponding backend account ID. Using researcher-controlled accounts, the chain was:

email -> accountId -> password reset -> login with the new password

I verified the state change by confirming that the previous password stopped working and the newly selected password successfully returned a valid session.

The research also covered the app authentication mechanism used by the Android client, email ownership verification during registration, and the wider SmartLife/Homecare SDK surface available after login.

ZTE patched the reported issues and assigned CVE-2026-86552, CVE-2026-86553, CVE-2026-86554 and CVE-2026-86555.

submitted by /u/TheReedemer69
[link] [comments]
Received β€” 17 August 2026 ⏭ /r/netsec - Information Security News & Discussion

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling

Technical analysis of CVE-2026-6837, an authenticated command-injection vulnerability in Zyxel’s PKCS#12 certificate export flow.

The post covers the vulnerable execution path, root cause, affected firmware scope, and the firmware-emulation methodology used during analysis.

submitted by /u/TheReedemer69
[link] [comments]
❌