CVE-2021-21745
ZTE mf971r_firmware Cross-Site Request Forgery (CSRF)
Record summary
CVE-2021-21745 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
mf971r_firmwareBrowse ZTE / mf971r_firmware | VulnCheck | Version data not supplied | |
MF971R | CVE List | BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMZTE MF971R - Referer authentication bypassCVSS 4.3
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
Impact
An attacker can bypass authentication and gain unauthorized access to the router.
Remediation
Apply the latest firmware update provided by ZTE to fix the authentication bypass vulnerability.
Source: ProjectDiscovery