CVE-2021-21731

HIGH

ZXCLOUD iRAI < 6.03.04 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
zte/zxcloud_irai < 6.03.04
Published Apr 13, 2021
Tracked Since Feb 18, 2026