HIGH🇵🇱 Wersja polska

CVE-2021-21744

CVSS 7.5v3.1pub. 2021-10-20upd. 2024-11-21

ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of the device to be disabled.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Zte Mf971r

    HW
    Zte
    all versions
  • Zte Mf971r Firmware

    OS
    Zte
    1v1.0.0b062v1.0.0b03s2v1.0.0b03sv1.0.0b05v1.0.0b05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-21748CRITICAL9.8PL ✓same product

Stack-based buffer overflow w ZTE MF971R — możliwość RCE

CVE-2021-21749CRITICAL9.8PL ✓same product

ZTE MF971R — krytyczne podatności stack-based buffer overflow umożliwiające RCE

CVE-2021-21743MEDIUM4.3same product

ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify t...

CVE-2021-21745MEDIUM4.3same product

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackerco...

CVE-2021-21746MEDIUM6.1same product

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie ...