CVE-2021-21741

CRITICAL

ZTE Zxv10 M910 Firmware - Insecure Deserialization

Title source: rule

Description

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

Scores

CVSS v3 9.8
EPSS 0.0135
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (4)

zte/zxv10_m910_firmware
zte/zxv10_m910_firmware
zte/zxv10_m910_firmware
zte/zxv10_m910_firmware

Timeline

Published Aug 30, 2021
Tracked Since Feb 18, 2026