The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 13 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations. | |
| Title | ZTE ZXEDM iEMS product has a password reset vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-04-13T06:31:49.372Z
Reserved: 2026-04-13T03:09:12.226Z
Link: CVE-2026-40436
No data.
Status : Received
Published: 2026-04-13T07:16:50.393
Modified: 2026-04-13T07:16:50.393
Link: CVE-2026-40436
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.