CVE-2026-40003 is an arbitrary memory write vulnerability in the ZTE ZX297520V3 BootROM. The flaw exists in the BootROM USB download mode because the target address for downloaded data is not properly validated. An attacker interacting with the device over USB can supply crafted download parameters that cause data to be written to attacker-chosen locations in BootROM runtime memory. By overwriting sensitive memory regions such as the stack, an attacker can corrupt control data, hijack execution flow, and subvert the normal boot process. The provided context further indicates that this can be used to bypass the Secure Boot signature verification mechanism and execute unauthorized code during early boot.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Rust-based exploit PoC for CVE-2026-40003 ('Joselito'), an arbitrary memory write vulnerability in the BootROM USB download mode of the ZXIC/Sanechips ZX297520V3 SoC. The repo is organized as a Cargo workspace with two main components: a host-side loader (`loader/`) and a bare-metal ARM payload (`payload/`). The host loader is the primary exploit component. It enumerates USB devices and waits for a target exposing USB VID:PID 19d2:0256, claims interface 0, and communicates over bulk endpoints 0x01 (OUT) and 0x81 (IN). It performs the BootROM handshake using sync byte 0x5A and expects device ACK 0xA5. It then uploads a stage-1 binary to address 0x00082000 using command 0x7A, which the vulnerable BootROM accepts without validating the destination address. Next, it abuses the same write primitive to overwrite saved registers on the BootROM stack at 0x81FD0 with repeated copies of 0x00082001, the Thumb entrypoint of the uploaded payload. Finally, it sends jump command 0x8A. The exploit relies on image verification failure causing control flow to return through `usbdl_init`, where `POP {R4, PC}` consumes the attacker-controlled stack values and transfers execution to the payload. The included payload is a demonstration-stage binary for ARMv6-M, linked at a fixed address via `payload/payload.ld`. It is `no_std`/`no_main` Rust with a small assembly stub. Once executed, it writes status strings to UART using MMIO registers at 0x01408004 and 0x01408014, reads efuse-related registers at 0x121b004/0x121b014 and dumps words from 0x0121b040 onward, then triggers a reset by writing to 0x13b000. This shows successful unsigned code execution in BootROM context rather than providing a generalized post-exploitation framework. Repository structure is straightforward: top-level workspace manifests, `loader/src/main.rs` implementing the exploit logic, `loader/src/err.rs` defining error handling, and `payload/` containing the embedded payload source, linker script, target specification, and build script. The README thoroughly documents the vulnerability, exploitation method, memory layout, stack offset calculation, and build/run steps. There are no network C2 endpoints or remote callbacks; the attack vector is local/physical over USB against a device in BootROM download mode.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.