CVE-2026-40003 Details
Description
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.
A vulnerability in the ZTE ZX297520V3 BootROM allows arbitrary memory writes via USB. This issue arises from inadequate validation of target addresses in USB download mode, enabling attackers to write data to any location in BootROM runtime memory. Exploitation of this vulnerability can overwrite the stack, hijack execution flow, bypass Secure Boot signature verification, and result in unauthorized code execution.
It is recommended to physically reinforce in-service equipment by sealing USB download test points, installing physical locks on enclosures, and prohibiting unauthorized disassembly.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2144487415169560645 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zte zx297520v3 firmware | All versions |
CPE
Remediation
| |
| zte zx297520v3 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | Initial Analysis | [email protected] |
| May 7, 2026 | New CVE Received | [email protected] |