CVE-2026-40000
LOW
1.8
CVSS 3.1
Description
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.
Metadata
Severity & Metrics
1.8
LOW CVSS 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| ZTE | Blade A75 5G | — | A75 series project, versions released before 2026/05/30 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-22 | cna | CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 1.8 | LOW | 3.1 | cna | CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |
References (1)