Zte · Zte File Manager · CVE-2026-40000
**Name of the Vulnerable Software and Affected Versions**
ZTE File Manager (affected versions not specified)
**Description**
The `zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity` activity is intended to preview compressed files. Third-party applications can launch this activity and provide arbitrary file paths, such as `content://zte.com.cn.filer.fileprovider/root path`, to access files using the privilege level of ZTE File Manager. This allows unrooted devices to read files in system directories including `/data/data` and `/data/local/tmp`. Depending on access restrictions, other directories may also be accessible.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.