The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zte
Zte zxedm Iems |
|
| Vendors & Products |
Zte
Zte zxedm Iems |
Mon, 13 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations. | |
| Title | ZTE ZXEDM iEMS product has a password reset vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-04-13T13:01:38.521Z
Reserved: 2026-04-13T03:09:12.226Z
Link: CVE-2026-40436
No data.
Status : Received
Published: 2026-04-13T07:16:50.393
Modified: 2026-04-13T07:16:50.393
Link: CVE-2026-40436
No data.
OpenCVE Enrichment
Updated: 2026-04-13T12:36:52Z