The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.
References
| Link | Resource |
|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/support/bulletin/security?lang=en_US&t=0.7465962531829456 | Vendor Advisory |
Configurations
History
12 May 2026, 19:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:zte:zxesm_iems:16.25.42.04:*:*:*:*:*:*:* | |
| First Time |
Zte zxesm Iems
|
06 May 2026, 19:08
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:zte:zxedm_iems:16.25.42.04:*:*:*:*:*:*:* | |
| References | () https://support.zte.com.cn/zte-iccp-isupport-webui/support/bulletin/security?lang=en_US&t=0.7465962531829456 - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| First Time |
Zte zxedm Iems
Zte |
13 Apr 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-13 07:16
Updated : 2026-05-12 19:10
NVD link : CVE-2026-40436
Mitre link : CVE-2026-40436
CVE.ORG link : CVE-2026-40436
JSON object : View
Products Affected
zte
- zxesm_iems
CWE
