{"id":"CVE-2026-86553","published":"2026-09-20T04:17:06.240","lastModified":"2026-09-22T19:41:38.447","description":"SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together with the target account ID, the attacker can reset the password of the target account.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2171542593031840100","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The SmartLife app generates authentication parameters dynamically, allowing an attacker to call the backend interface to obtain account IDs and reset passwords, posing a significant security risk.","exploitability":"Exploitation requires access to the SmartLife app and knowledge of the backend interface, making it moderately difficult.","blast_radius":"If exploited, this flaw could lead to unauthorized password resets and account takeovers, affecting user data and trust.","remediation":"Disable the dynamic generation of authentication parameters or restrict access to the /account/verify.serv endpoint.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","password-reset","backend-exploit"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:19:42.705Z"}}