CVE-2026-40004
Awaiting Analysis
Awaiting Analysis - Queue
Privilege Escalation in ZTE Cloud PC uSmartview via OpenSSL.cnf
Publication date: 2026-05-07
Last updated on: 2026-05-07
Assigner: ZTE Corporation
Description
Description
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zte | cloud_pc_client_usmartview | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |