CVE-2026-40003

MEDIUM CVSS 3.1: 6.8 EPSS 0.30%
Updated Jun 17, 2026
Zte
Parameter Value
CVSS 6.8 (MEDIUM)
Type CWE-787 (Out-of-bounds Write)
Vendor Zte
Public PoC No

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

Attack Parameters

Attack Vector
Physical
Requires physical access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Zte Zx297520v3_Firmware
cpe:2.3:o:zte:zx297520v3_firmware:-:*:*:*:*:*:*:*
Zte Zx297520v3
cpe:2.3:h:zte:zx297520v3:-:*:*:*:*:*:*:*