TROYANOSYVIRUS
Volver a CVEs

CVE-2026-40003

MEDIUM
5.1

Descripcion

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

Detalles CVE

Puntuacion CVSS v3.15.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Vector de ataquePHYSICAL
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado5/7/2026
Ultima modificacion5/7/2026
Fuentenvd
Avistamientos honeypot0

Debilidades (CWE)

CWE-787

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.