CVE-2026-40003Disclosure(zte / zx297520v3)

MEDIUMCVSS 6.8 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch zte zx297520v3 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zx297520v3
  • zx297520v3_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-07); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
zx297520v3zx297520v3_firmware

1 version affected across 2 products

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-07: 4Mentions · 2026-06-28: 1Mentions · 2026-07-02: 1Mentions · 2026-07-14: 1PoC Mentioned / Linked · 2026-06-28: 1Active Exploitation · 2026-07-14: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-05-07: 3Technical Details · 2026-06-28: 1Technical Details · 2026-07-14: 105-0706-2807-0207-14
Signal classification2 categories
Disclosure
685.7%
Active Exploitation
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-074
Disclosure4
2026-06-281
Disclosure1
2026-07-021
Disclosure1
2026-07-141
Active Exploitation1
Full discourse7 posts
  • Alex de la cruz@lexs17
    Active Exploitation

    : *CVE-2026-40003: Operation Silent Rescue - Penta Chain* *Title*: Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM *CVSS 3.1*: 9.8 Critical `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` *CWE*: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 *Affected*: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 *Credit*: Independent Security Research (Latin America Division) *Status*: Active Threat. Coordinated disclosure submitted to Rapid7, AttackerKB, CISA, Unisoc PSIRT, Motorola Security on June 26, 2026. Public Disclosure: September 24, 2026 *1. Executive Summary* "Operation Silent Rescue" identifies a *systemic attack chain affecting millions of budget Android devices in Latin America*. The vulnerability is not a single bug but a *convergence* of: 1. *Unpatchable Hardware Flaws*: Permanent BootROM exploits CVE-2022-38694. 2. *Remote Network Vectors*: Modem RCE via rogue cell towers CVE-2025-31718. 3. *Privileged System Backdoors*: Pre-installed apps `com.spreadtrum.sgps`, `http://com.android.stk`, `com.dti.amx`, `com.inmobi.installer` with exported components and *God-mode permissions* `INSTALL_PACKAGES`, `WRITE_SECURE_SETTINGS`. This chain allows an attacker to move from *remote network access to full system root, persistent surveillance, and financial fraud without user interaction*. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. *2. The Attack Chain: Technical Breakdown* *Phase 1: The Foundation (Hardware & Network)* - *CVE-2022-38694 (BootROM)*: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. *Impact*: Permanent rootkits, bypass of Secure Boot. - *CVE-2025-31718 (Modem RCE)*: Remote code execution via malformed LTE signals. *Impact*: Over-the-air initial access `AV:N` without user interaction. *Phase 2: The Escalation Bridges (Exported System Apps)* Once initial access is gained, the following system apps act as *force multipliers*, escalating privileges from "modem context" to "full system control": **Component****Package Name****Critical Flaw****Role in Chain** **SGPS Middleware**`com.spreadtrum.sgps`Exported Receiver. `InstallDate: 2008-12-31`. `REBOOT` permission.**Primary LPE Vector**. Triggers via code `2266`. Enables `NMEA2SOCKET`. **SIM Toolkit**`http://com.android.stk`Exported Receiver. Runs in `http://com.android.phone`.**Financial Fraud**. Pre-auth phishing via `BootCompletedReceiver`. **Modem Stats**`com.motorola.bach.modemstats`Exported `READ_LOGS`, `MODIFY_PHONE_STATE`. `persistent=true`.**C2 & Persistence**. Hidden backchannel + call interception. **Digital Turbine**`com.dti.amx``INSTALL_PACKAGES`, `WRITE_SECURE_SETTINGS`.**Payload Delivery 1**. Silently installs banking trojans. Disables Play Protect. **InMobi Installer**`com.inmobi.installer`Exported `InstallationService`. `QUERY_ALL_PACKAGES`.**Payload Delivery 2**. Public API for silent installation. **Redundant backdoor**. *Phase 3: The Payload (Surveillance & Fraud)* - *Financial Theft*: Use `INSTALL_PACKAGES` to drop banking trojans. Use `STK` to send premium SMS or intercept 2FA codes. - *Surveillance*: Use `SGPS` for real-time location tracking. Use `ModemStats` for call interception and IMSI catching. - *Persistence*: Use `BootCompletedReceiver` in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. *3. Regional Impact: Latin America (LATAM)* - *Market Share*: Motorola + Unisoc devices dominate the budget sector in Mexico, Brazil, Argentina, and Colombia. - *Vulnerable Demographics*: Users rely on these single devices for banking, government ID, and commerce. - *Patch Latency*: Security updates are delayed by 6-12 months. *BootROM flaws are never patched*. - *Bloatware Risk*: Aggressive pre-installation of Digital Turbine and InMobi creates a *"dual backdoor" environment* unique to this region's carrier variants. *4. Critical Conclusion: The Systemic Escalation Risk* The core finding of "Operation Silent Rescue" is that *hardware vulnerabilities alone are not the primary threat; the true danger lies in the system software architecture that exposes privileged interfaces to the entire OS*. 1. *From Local to Global*: A local bug like exported SGPS receiver becomes a *global remote threat* when chained with Modem RCE. 2. *Trust Violation*: Android's security model relies on app sandboxing. These system apps *violate that trust* by holding `INSTALL_PACKAGES` and `WRITE_SECURE_SETTINGS`, effectively acting as *rootkits with legal signatures*. 3. *No Clean Path*: Because the backdoors `com.dti.amx`, `com.inmobi.installer` are in `/system/priv-app`, users *cannot remove them* without unlocking the bootloader which triggers the BootROM exploit risk. 4. *Inevitable Compromise*: On an unpatched Unisoc device, compromise is not a matter of "if" but "when." A single rogue cell tower or malicious app is sufficient. *Final Verdict*: This is a *Critical Systemic Failure*. The combination of *unpatchable hardware, remote modem flaws, and exported privileged system apps* creates a permanent, pre-auth surveillance and fraud platform. *5. Recommendations* - *For Users (LATAM)*: Avoid Unisoc T606/T616 devices for banking. Use feature phones or older, patched Qualcomm devices for sensitive transactions. - *For Enterprises/MDM*: Blocklist all Motorola Unisoc T606/T616 models. Flag `com.dti.amx` and `com.inmobi.installer` as critical IoCs. - *For Motorola/Unisoc*: *Immediate*: Disable `exported="true"` on SGPS, STK, ModemStats. *Long-term*: Recall hardware with BootROM flaws. Remove `INSTALL_PACKAGES` from third-party bloatware. - *For Security Vendors*: Update detection signatures to monitor for *silent install events* from `com.dti.amx` and `com.inmobi.installer`, and flag *SGPS socket activity* as suspicious. *IoCs*: 1. `com.spreadtrum.sgps` with `InstallDate: 2008-12-31` 2. `http://com.android.stk` in `http://com.android.phone` process 3. `com.motorola.bach.modemstats` with `persistent=true` 4. `com.dti.amx` disguised as `Notificaciones` with `INSTALL_PACKAGES` 5. `com.inmobi.installer` with exported `InstallationService`

    Post summary

    The report details a critical, actively exploited vulnerability chain for CVE‑2026‑40003 in Latin America devices, offering specific threat and mitigation information but no PoC or exploit code.

    00011208
    177 followersView on X
  • Alex de la cruz@lexs17
    Disclosure

    Honored to see Brave AI confirm that CVE-2026-40003 'Penta Chain' was a coordinated disclosure, not a leak. Coordinated with CISA, Rapid7, Motorola Security, and Unisoc PSIRT on June 26, 2026. Let's go Full technical breakdown on AttackerKB @AttackerKb @rapid7 @SecurityTube https://t.co/5CySnTQVtX

    Post summary

    The tweet confirms a coordinated disclosure of CVE-2026-40003 with several security organizations and points to a technical breakdown, but does not provide exploitation or mitigation details.

    00000112
    161 followersView on X
  • Alex de la cruz@lexs17
    Disclosure

    I just published Operation Silent Rescue v1.0 CVE-2026-40003: Unisoc T606 supply-chain backdoor 47M+ devices affected in LATAM Includes: YARA, Snort, IOCs, mitigation without root http://github.com/lexs201992-gif/motorola-g04s-t606-spreadtrum #infosec #cve #android #unisoc #latam @rapid7 @AttackerKb

    Post summary

    The author announces Operation Silent Rescue v1.0 for CVE-2026-40003, providing detection rules, IOCs, and a rootless mitigation via a GitHub repository.

    00000102
    153 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40003 ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB do… https://www.cve.org/CVERecord?id=CVE-2026-40003 ----- Traducción: CVE-2026-40003 ZTE… http://infoflow.cloud`

    Post summary

    CVE-2026-40003 exposes an arbitrary memory write flaw in the ZTE ZX297520V3 BootROM caused by missing USB target address validation.

    00000168
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40003 ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB do… https://www.cve.org/CVERecord?id=CVE-2026-40003

    Post summary

    CVE‑2026‑40003 describes a memory write vulnerability in the ZTE ZX297520V3 BootROM that arises from missing target-address validation when handling USB input.

    00000254
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40003 📊 Severity: 5.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40003 #CVE-2026-40003 #CVE #Medium #CyberSecurity #InfoSec https://t.co/saxZCQMo8X

    Post summary

    An announcement of CVE-2026-40003 with a medium CVSS score; no further technical, exploit, or patch information is provided.

    0000035
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40003 Arbitrary Memory Write Vulnerability in ZTE ZX297520V3 BootROM via USB https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40003

    Post summary

    The brief announcement describes an arbitrary memory write flaw in the ZTE ZX297520V3 BootROM accessed through USB, without any mention of PoC, exploitation, or remediation.

    00000146
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWztezx297520v3---
OSztezx297520v3_firmware---

Explore more