CVE-2022-39075

HIGH

ZTE Mobile Phones - Info Disclosure

Title source: llm
STIX 2.1

Description

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (17)
zte/axon_40_ultra_firmware < 1.0.0b26
zte/blade_a31_firmware < m03
zte/blade_a31_plus_firmware < m04
zte/blade_a3_lite_firmware < m09
zte/blade_a51_firmware < m07
zte/blade_a52_firmware < m02
zte/blade_a5_2019_firmware < m13
zte/blade_a5_2020_firmware < m05
zte/blade_a71_firmware < 2.4
zte/blade_a72_firmware < 11.0.3
... and 7 more
Published May 30, 2023
Tracked Since Feb 18, 2026