4.3
CVSSv3

CVE-2021-21745

Published: 20/10/2021 Updated: 25/10/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zte mf971r_firmware v1.0.0b05

zte mf971r_firmware 1v1.0.0b06

zte mf971r_firmware 2v1.0.0b03

zte mf971r_firmware s2v1.0.0b03

zte mf971r_firmware sv1.0.0b05

Vendor Advisories

Check Point Reference: CPAI-2021-2150 Date Published: 3 Apr 2024 Severity: Medium ...