CVE-2021-21722

MEDIUM

ZTE ZXV10 B860A Firmware V2.1-T_V0032.1.1.04_jiangsuTelecom - Sensitive Information Exposure via Log File

Title source: llm
STIX 2.1

Description

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
zte/zxv10_b860a_firmware v2.1-t_v0032.1.1.04_jiangsutelecom
Published Jan 14, 2021
Tracked Since Feb 18, 2026