← Volver a CVEs
CVE-2026-40003
MEDIUM5.1
Descripcion
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.
Detalles CVE
Puntuacion CVSS v3.15.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Vector de ataquePHYSICAL
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado5/7/2026
Ultima modificacion5/7/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-787
Referencias
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.