ZTE SmartLife flaws allow account takeover without reset code
Brief
Security researcher Mina Nageh Salama disclosed a chain of vulnerabilities in ZTE’s SmartLife platform that lets attackers take over user accounts by resetting passwords without a verification code. ZTE confirmed four flaws, issued CVE identifiers, and said it fully patched the vulnerabilities on September 3, 2026. However, users must apply security updates to protect their …
The post ZTE SmartLife flaws allow account takeover without reset code appeared first on CyberInsider .
