Description
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.
Published: 2026-07-27
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the FilePreViewActivity of the ZTE File Manager, which accepts arbitrary file paths from third‑party applications. An attacker can supply paths that point to protected system locations such as /data/data or /data/local/tmp. By exploiting this oversight, the attacker gains read access to files with the same privileges as the trusted file manager, potentially exposing sensitive data without requiring root access.

Affected Systems

ZTE Blade A75 5G is affected. No specific firmware or software version numbers were disclosed, so all installed copies of the device are potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS score is 1.8, indicating low severity, and the EPSS score is < 1%. The vulnerability is not listed in KEV. The attack requires a malicious or compromised third‑party application that can launch the vulnerable activity, suggesting a local or "same‑device" threat model. While the impact is limited to file disclosure and does not enable remote code execution, the data exposure risk remains if sensitive files reside in the accessible directories.

Generated by OpenCVE AI on August 3, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Seek and apply any official firmware or software update from ZTE that addresses the FilePreViewActivity exposure.
  • Avoid installing or enabling untrusted third‑party applications that could target or launch the vulnerable activity.
  • Enforce tighter inter‑application communication controls, such as adjusting app permissions or using a security overlay to monitor and block unintended activity launches.

Generated by OpenCVE AI on August 3, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in ZTE Blade A75 Pro 5G Path Traversal Vulnerability in ZTE Blade A75 5G

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte a75 Pro 5g
Vendors & Products Zte
Zte a75 Pro 5g

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.
Title Path Traversal Vulnerability in ZTE Blade A75 Pro 5G
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 1.8, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-07-28T11:04:11.498Z

Reserved: 2026-04-08T07:51:26.674Z

Link: CVE-2026-40000

cve-icon Vulnrichment

Updated: 2026-07-27T10:23:26.576Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T10:16:37.907

Modified: 2026-07-28T16:07:15.840

Link: CVE-2026-40000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')