CVE-2026-40436Disclosure(zte / zxesm_iems)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch zte zxesm_iems systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zxesm_iems

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
zxesm_iems

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-13: 3Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 204-13
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40436 The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user… https://www.cve.org/CVERecord?id=CVE-2026-40436

    Post summary

    CVE‑2026‑40436 identifies a password‑reset flaw in ZTE ZXEDM iEMS’s cloud EMS portal caused by inadequate user access controls.

    00000246
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40436 Password Reset Vulnerability in ZTE ZXEDM iEMS Cloud EMS Portal https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40436

    Post summary

    The note announces CVE-2026-40436 as a password‑reset vulnerability affecting the ZTE ZXEDM iEMS Cloud EMS Portal and provides only a brief description and a link to a vulnerability database, with no further exploitation, patch, or technical detail.

    00000154
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-40436 (CVSS 7.1) - ZTE ZXEDM iEMS password reset vuln allows attackers to reset ANY user password via exposed user list API. Unauthorized access risk. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/gP9jkuAQT4

    Post summary

    The tweet reports CVE-2026-40436, a password‑reset flaw in ZTE ZXEDM iEMS that lets attackers change any user’s password via an exposed API, and urges immediate patching.

    00000172
    25 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appztezxesm_iems16.25.42.04--

Explore more