ZTE ZX297520V3是中国中兴通讯(ZTE)公司的一款工业级4G模组。 ZTE ZX297520V3存在缓冲区错误漏洞,该漏洞源于USB下载模式缺乏目标地址验证,可能导致任意内存写入,进而覆盖堆栈、劫持执行流程、绕过安全启动签名验证机制并实现未授权代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZTE | ZX297520V3 BootROM | 7520V3 chip |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZTE | ZX297520V3 BootROM | 7520V3 chip | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44406 | 5.7 MEDIUM | DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview |
| CVE-2026-40004 | 5.5 MEDIUM | openssl.cnf Privilege Escalation Vulnerability in ZTE Cloud PC Client uSmartview |
| CVE-2026-44407 | 4.7 MEDIUM | Remote Denial of Service Vulnerability Exists in ZTE Cloud PC Client uSmartview |
No comments yet