Record summary

CVE-2021-21745 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

MF971R

CVE ListBD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05affected

Nuclei templates

1
ProjectDiscoveryMEDIUMZTE MF971R - Referer authentication bypassCVSS 4.3

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

Impact

An attacker can bypass authentication and gain unauthorized access to the router.

Remediation

Apply the latest firmware update provided by ZTE to fix the authentication bypass vulnerability.

WeaknessesCWE-352
Authorsgy741
Template tagscve2021cvezteauth-bypassroutervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CPE: cpe:2.3:o:zte:mf971r_firmware:v1.0.0b05:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2