There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
History

Thu, 07 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 May 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxcloud Irai
Vendors & Products Zte
Zte zxcloud Irai

Thu, 07 May 2026 04:15:00 +0000

Type Values Removed Values Added
Description There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
Title openssl.cnf Privilege Escalation Vulnerability in ZTE Cloud PC Client uSmartview
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published: 2026-05-07T03:47:06.297Z

Updated: 2026-05-07T12:41:25.248Z

Reserved: 2026-04-08T07:51:26.675Z

Link: CVE-2026-40004

cve-icon Vulnrichment

Updated: 2026-05-07T12:41:17.934Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-07T04:16:23.073

Modified: 2026-05-07T14:56:04.523

Link: CVE-2026-40004

cve-icon Redhat

No data.