CVE-2026-40000: Path Traversal Vulnerability in ZTE Blade A75 5G
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/rootpath), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure access restrictions block untrusted applications from launching ZTE File Manager’s Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity, so third-party apps cannot supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path) to read files with ZTE File Manager’s privileges.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40000?
The severity of CVE-2026-40000 is classified as low with a score of 1.8.
How do I fix CVE-2026-40000?
To mitigate CVE-2026-40000, ensure that the ZTE File Manager is updated to the latest version provided by ZTE.
What type of vulnerability is identified in CVE-2026-40000?
CVE-2026-40000 is identified as a Path Traversal vulnerability.
Which software is affected by CVE-2026-40000?
CVE-2026-40000 affects the ZTE File Manager on ZTE devices.
What impact does CVE-2026-40000 have?
CVE-2026-40000 allows third-party applications to access arbitrary file paths, potentially leading to unauthorized file access.