ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NZte Mf971r
HWZtewszystkie wersjeZte Mf971r Firmware
OSZte1v1.0.0b062v1.0.0b03s2v1.0.0b03sv1.0.0b05v1.0.0b05
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Powiązane podatności
CVE-2021-21748CRITICAL9.8PL ✓ten sam produkt
Stack-based buffer overflow w ZTE MF971R — możliwość RCE
CVE-2021-21749CRITICAL9.8PL ✓ten sam produkt
ZTE MF971R — krytyczne podatności stack-based buffer overflow umożliwiające RCE
CVE-2021-21744HIGH7.5ten sam produkt
ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to...
CVE-2021-21743MEDIUM4.3ten sam produkt
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify t...
CVE-2021-21746MEDIUM6.1ten sam produkt
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie ...