Back to overview

CVE-2026-40000

LOW
1.8
CVSS 3.1
Description
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.

Metadata

CVE ID
CVE-2026-40000
State
PUBLISHED
Assigner
zte
Reserved
2026-04-08 07:51 UTC
Published
2026-07-27 09:35 UTC
Last updated
2026-07-28 11:04 UTC
Primary CWE
CWE-22
CWE-22Improper Limitation of a Pathname to a Restricted Dire…
Vendor / Product
ZTE / Blade A75 5G
Sources
cve.org  ·  NVD

Severity & Metrics

1.8 LOW CVSS 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
ZTE Blade A75 5G A75 series project, versions released before 2026/05/30
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
1.8 LOW 3.1 cna CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Back to overview