CVE-2026-40003
Received Received - Intake
BaseFortify

Publication date: 2026-05-07

Last updated on: 2026-05-07

Assigner: ZTE Corporation

Description
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-07
Last Modified
2026-05-07
Generated
2026-05-07
AI Q&A
2026-05-07
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zte zx297520v3_bootrom *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability exists in the ZTE ZX297520V3 BootROM and allows attackers to perform arbitrary memory writes via USB.

This happens because the USB download mode does not validate the target address, enabling attackers to write data to any location in the BootROM runtime memory.

By doing so, attackers can overwrite the stack, hijack the execution flow, bypass the Secure Boot signature verification mechanism, and execute unauthorized code.


How can this vulnerability impact me? :

This vulnerability can have serious impacts including unauthorized code execution on the affected device.

Attackers exploiting this flaw can hijack the device's execution flow and bypass security mechanisms like Secure Boot, potentially leading to device compromise.

Such unauthorized access could result in data manipulation, disruption of device functionality, or use of the device for malicious purposes.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart