Junglewise Threat Intelligence

CVE-2026-40004: ZTE uSmartview privilege escalation via openssl.cnf search path

CVE-2026-40004 · Severity: medium · CVSS 5.5 · Published 2026-05-07

Vendors: Zte.

Executive brief

A security vulnerability exists in the ZTE uSmartview Cloud PC client, a tool used for accessing virtual desktop environments. An attacker with physical or local access to a computer running this software can exploit a configuration flaw to gain higher-level administrative permissions. This could allow an unauthorized user to take full control of the system, access sensitive data, or disrupt business operations.

Technical details

The ZTE uSmartview Cloud PC client (ZXCloud iRAI) is vulnerable to an uncontrolled search path (CWE-427) involving the openssl.cnf configuration file. Because the application does not properly validate or secure the path from which it loads this configuration, a local attacker can place a malicious configuration file in a directory searched by the application. When the application loads the malicious file, it can be forced to execute arbitrary code or load malicious libraries. This allows a low-privileged local user to escalate their privileges to those of the application, typically administrative or system-level. The vulnerability affects versions from 7.23.20 up to (but excluding) 7.25.43.

Affected products

  • ZTE uSmartview (ZXCloud iRAI) 7.23.20 to 7.25.43

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: advisory

References

Related threats