CVE-2026-40002: ZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations.
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40002?
CVE-2026-40002 has been classified with a medium severity rating due to its potential exploitation by non-privileged applications.
How do I fix CVE-2026-40002?
To fix CVE-2026-40002, users should apply the latest software updates provided by ZTE for the Red Magic 11 Pro (NX809J).
What types of operations can be triggered by exploiting CVE-2026-40002?
Exploiting CVE-2026-40002 allows non-privileged applications to perform sensitive operations that should be restricted.
Who is affected by CVE-2026-40002?
CVE-2026-40002 affects users of the ZTE Red Magic 11 Pro (NX809J) smartphone.
Is CVE-2026-40002 actively being exploited in the wild?
As of now, there are no reported instances of CVE-2026-40002 being actively exploited in the wild.