---
id: CVE-2026-40002
title: "Red Magic 11 Pro (NX809J)\_contains a vulnerability that allows non-privileged applications to trigger sensitive operations"
summary: "Red Magic 11 Pro (NX809J)\_contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting …"
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-269
vendor: zte
product: nubia-in_nx809j_firmware
affected:
  - nubia-in_nx809j_firmware < GEN_NEEA_NX809JV1.0.0B16MR1
patched:
  - nubia-in_nx809j_firmware GEN_NEEA_NX809JV1.0.0B16MR1
published: '2026-04-17'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40002'
references:
  - url: >-
      https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/8224335890517684583
    label: psirt@zte.com.cn
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.03158
ingestedAt: '2026-07-08T03:46:38.653Z'
---

## Overview

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties.

## Affected

- `nubia-in_nx809j_firmware < GEN_NEEA_NX809JV1.0.0B16MR1`

## Remediation

Upgrade past the affected range:

- `nubia-in_nx809j_firmware GEN_NEEA_NX809JV1.0.0B16MR1`
