CVE-2026-40004: ZTE Zxcloud Irai
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
Affected products
- ZTE Zxcloud Irai: from 7.23.20, before 7.25.43 (fixed in 7.25.43)
Published 2026-05-07. Last modified 2026-06-17.