CVE-2026-40000

LOW

ZTE Blade A75 Pro 5G File Manager - Path Traversal File Read

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-40000. PoCs published by Skorpion96.

AI-analyzed exploit summary This PoC exploits an improper intent handling vulnerability in the ZTE Filer app (zte.com.cn.filer) by crafting a malicious Android intent to access arbitrary files via the app's file provider. The exploit leverages the `FilePreViewActivity` component to read files without proper path validation.

Description

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.

Exploits (1)

github WORKING POC
by Skorpion96 · javapoc
https://github.com/Skorpion96/CVE-2026-40000

This PoC exploits an improper intent handling vulnerability in the ZTE Filer app (zte.com.cn.filer) by crafting a malicious Android intent to access arbitrary files via the app's file provider. The exploit leverages the `FilePreViewActivity` component to read files without proper path validation.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: ZTE Filer app (zte.com.cn.filer), likely specific versions vulnerable to improper intent handling
No auth needed
Prerequisites: Android device with the vulnerable ZTE Filer app installed · User interaction to launch the malicious intent (e.g., via a crafted app or ADB)
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →

Scores

CVSS v3 1.8
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
ZTE/A75 Pro 5G A75 Pro series project, versions released before 2026/05/30
ZTE/Blade A75 5G A75 series project, versions released before 2026/05/30
Published Jul 27, 2026
Tracked Since Jul 27, 2026