Executive brief
A security vulnerability exists in the startup code of the ZTE ZX297520V3 chipset, which is used in various telecommunications and networking hardware. An attacker with physical access to the device can use the USB port to bypass security protections that normally ensure only authorized software can run. This could allow an attacker to gain full control over the device, potentially leading to permanent modification of the hardware's behavior or unauthorized access to data processed by the device.
Technical details
The ZTE ZX297520V3 BootROM suffers from an out-of-bounds write vulnerability (CWE-787) due to insufficient validation of target addresses during USB download mode operations. By connecting to the device via USB, a physically present attacker can perform arbitrary memory writes to the BootROM runtime memory. This capability allows for stack smashing and control flow hijacking. Successfully exploiting this flaw enables the attacker to bypass Secure Boot signature verification, leading to the execution of unsigned, unauthorized code at the highest privilege level during the boot process.
Affected products
- ZTE ZX297520V3 firmware All versions prior to May 2026 update
Timeline
- 2026-05-07: advisory: Initial disclosure by ZTE Corporation