CVE 5.1 MEDIUM

USB-based arbitrary memory write vulnerability in ZTE ZX297520V3 soc BootROM_CVE-2026-40003

5.1 / 10
MEDIUM
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L

Description

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

Basic Information

ID CVE-2026-40003
Source zte
Published May 7, 2026 at 01:15

Affected Product

Vendor ZTE
Product ZX297520V3 BootROM
Version 7520V3 chip
Affected Versions ZTE ZX297520V3 BootROM 7520V3 chip

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.