Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties. | |
| Title | ZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2026-04-17T12:11:37.153Z
Reserved: 2026-04-08T07:51:26.675Z
Link: CVE-2026-40002
Updated: 2026-04-17T12:11:33.478Z
Status : Received
Published: 2026-04-17T08:16:18.120
Modified: 2026-04-17T08:16:18.120
Link: CVE-2026-40002
No data.
OpenCVE Enrichment
Updated: 2026-04-17T10:00:03Z