Executive brief
A security vulnerability has been identified in the ZTE uSmartview Cloud PC client, a tool used for accessing virtual desktop environments. An attacker could exploit this flaw to cause the application to crash or become unresponsive, potentially disrupting business operations and user access to their remote workstations. This issue is primarily a denial-of-service risk, meaning it affects the availability of the service rather than the confidentiality of user data.
Technical details
A denial-of-service vulnerability exists in the ZTE uSmartview client (part of the ZXCloud iRAI suite). The vulnerability is classified as a format string bug (CWE-134) where the application fails to properly validate externally-controlled format strings. This can lead to memory corruption when processing malicious input. While the vendor (ZTE) suggests a local attack vector with medium severity, NVD's analysis indicates a network-based attack vector (AV:N) with high severity, allowing an unauthenticated remote attacker to trigger a crash and cause a denial-of-service condition. The issue affects versions starting from 7.23.20 and is addressed in version 7.25.43.
Affected products
- ZTE uSmartview (ZXCloud iRAI) 7.23.20 to 7.25.43
Timeline
- 2026-05-07: disclosed: Initial disclosure by ZTE Corporation
- 2026-05-07: advisory: CVE-2026-44407 published
- 2026-05-11: other: NVD analysis and enrichment completed