CVE-2021-21722

MEDIUM

ZTE Zxv10 B860a Firmware - Log Information Exposure

Title source: rule
STIX 2.1

Description

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
zte/zxv10_b860a_firmware v2.1-t_v0032.1.1.04_jiangsutelecom
Published Jan 14, 2021
Tracked Since Feb 18, 2026