
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads
ZTESmartHomeaccount takeoverpassword resetvulnerabilityCVEsecurityAndroidauthentication bypass
A researcher reported four vulnerabilities in ZTE SmartLife, with the main issue being CVE-2026-86553, a password reset flaw that allowed changing account passwords without requiring a reset code, old password, or validated reset transaction. The attack chain involved using an endpoint that exposed whether an email was registered and returned the backend account ID, which could then be used to reset the password and take over the account. ZTE patched the reported issues and assigned four CVEs: CVE-2026-86552, CVE-2026-86553, CVE-2026-86554, and CVE-2026-86555.