Password Reset Vulnerability in ZTE ZXEDM iEMS Product
CVE-2026-40436

7.1HIGH

Key Information:

Vendor

Zte

Vendor
CVE Published:
13 April 2026

What is CVE-2026-40436?

The ZTE ZXEDM iEMS product has a significant security flaw that enables unauthorized users to reset passwords for any account. Due to insufficient access control in the cloud EMS portal's management system, attackers can access the user list interface and retrieve sensitive user information. This vulnerability allows malicious actors to perform unauthorized actions on behalf of other users, posing substantial security threats.

Affected Version(s)

ZXEDM iEMS ElasticNet_UME_R32_V16.25.42.04

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wenwei Shi
.