PT-2026-64874 · Zte · A75 Pro 5G

·

CVE-2026-40000

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

1.8

Low

VectorAV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40000

Affected Products

A75 Pro 5G