CVE-2022-39071: High severity zte blade a52 firmware vulnerability

Published May 30, 2023
·
Updated

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.

Affected Software

68 affected components
ZTE Blade A52 Firmware<m02
ZTE Blade A52
ZTE Blade A51 Firmware<m07
ZTE Blade A51
ZTE Blade A3 Lite Firmware<m09
ZTE Blade A3 Lite
ZTE Blade A5 2020 Firmware<m05
ZTE Blade A5 2020
ZTE Blade L210 Firmware<1.14
ZTE Blade L210
ZTE Blade A7s Firmware<2.2
ZTE Blade A7s
ZTE Blade A31 Firmware<m03
ZTE Blade A31
ZTE Blade A31 Plus Firmware<m04
ZTE Blade A31 Plus
ZTE Blade A5 2019 Firmware<m13
ZTE Blade A5 2019
ZTE Blade A71 Firmware<2.4
ZTE Blade A71
ZTE Blade A72 Firmware<11.0.3
ZTE Blade A72
ZTE Blade V20 Smart Firmware<1.14
ZTE Blade V20 Smart
ZTE Blade V30 Firmware<1.11
ZTE Blade V30
ZTE Blade V30 Vita Firmware<1.11
ZTE Blade V30 Vita
ZTE V40 Pro Firmware<11.0.4_9046
ZTE V40 Pro
ZTE Blade V40 Vita Firmware<11.0.2_8045
ZTE Blade V40 Vita
ZTE Axon 40 Ultra Firmware<1.0.0b26
ZTE Axon 40 Ultra
All of the following
ZTE Blade A52 Firmware<m02
ZTE Blade A52
All of the following
ZTE Blade A51 Firmware<m07
ZTE Blade A51
All of the following
ZTE Blade A3 Lite Firmware<m09
ZTE Blade A3 Lite
All of the following
ZTE Blade A5 2020 Firmware<m05
ZTE Blade A5 2020
All of the following
ZTE Blade L210 Firmware<1.14
ZTE Blade L210
All of the following
ZTE Blade A7s Firmware<2.2
ZTE Blade A7s
All of the following
ZTE Blade A31 Firmware<m03
ZTE Blade A31
All of the following
ZTE Blade A31 Plus Firmware<m04
ZTE Blade A31 Plus
All of the following
ZTE Blade A5 2019 Firmware<m13
ZTE Blade A5 2019
All of the following
ZTE Blade A71 Firmware<2.4
ZTE Blade A71
All of the following
ZTE Blade A72 Firmware<11.0.3
ZTE Blade A72
All of the following
ZTE Blade V20 Smart Firmware<1.14
ZTE Blade V20 Smart
All of the following
ZTE Blade V30 Firmware<1.11
ZTE Blade V30
All of the following
ZTE Blade V30 Vita Firmware<1.11
ZTE Blade V30 Vita
All of the following
ZTE V40 Pro Firmware<11.0.4_9046
ZTE V40 Pro
All of the following
ZTE Blade V40 Vita Firmware<11.0.2_8045
ZTE Blade V40 Vita
All of the following
ZTE Axon 40 Ultra Firmware<1.0.0b26
ZTE Axon 40 Ultra

Event History

May 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
11:15 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-39071 about?

CVE-2022-39071 is an unauthorized access vulnerability in some ZTE mobile phones that allows a malicious application to overwrite system configuration files and user installers without user permission.

2

Which ZTE mobile phones are affected by CVE-2022-39071?

ZTE Blade A52, ZTE Blade A51, ZTE Blade A3 Lite, ZTE Blade A5 2020, ZTE Blade L210, ZTE Blade A7s, ZTE Blade A31, ZTE Blade A31 Plus, ZTE Blade A5 2019, ZTE Blade A71, ZTE Blade A72, ZTE Blade V20 Smart, ZTE Blade V30, ZTE Blade V30 Vita, ZTE V40 Pro, ZTE Blade V40 Vita, and ZTE Axon 40 Ultra are affected by CVE-2022-39071.

3

What is the severity of CVE-2022-39071?

CVE-2022-39071 has a severity rating of 7.1, which is classified as high.

4

How can I fix CVE-2022-39071?

To fix CVE-2022-39071, ZTE mobile phone users should install the latest firmware update provided by ZTE to patch the vulnerability.

5

Where can I find more information about CVE-2022-39071?

You can find more information about CVE-2022-39071 on the ZTE support website at https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1030664.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203