CVE-2021-21741
CRITICALZTE Zxv10 M910 Firmware - Insecure Deserialization
Title source: ruleDescription
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.
Scores
CVSS v3
9.8
EPSS
0.0135
EPSS Percentile
79.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (4)
zte/zxv10_m910_firmware
zte/zxv10_m910_firmware
zte/zxv10_m910_firmware
zte/zxv10_m910_firmware
Timeline
Published
Aug 30, 2021
Tracked Since
Feb 18, 2026