Vulnerability Description
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zx297520V3 Firmware | - |
| Zte | Zx297520V3 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-40003?
CVE-2026-40003 is a vulnerability with a CVSS score of 5.1 (MEDIUM). ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any l...
How severe is CVE-2026-40003?
CVE-2026-40003 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40003?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zx297520V3 Firmware, Zte Zx297520V3.