← All CVEs

CVE-2021-21745

medium · 4.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

4.3
CVSS
55.7%
EPSS (exploit prob.)
99th
EPSS percentile
2021-10-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Weaknesses

CWE-352

Affected products

VendorProductAffected versions
ztemf971r_firmwarev1.0.0b05
ztemf971rall versions
ztemf971r_firmware1v1.0.0b06
ztemf971rall versions
ztemf971r_firmware2v1.0.0b03
ztemf971rall versions
ztemf971r_firmwares2v1.0.0b03
ztemf971rall versions
ztemf971r_firmwaresv1.0.0b05
ztemf971rall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-21745