Information Leak Vulnerability in ZTE Smart STB Device
CVE-2021-21722

4.4MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
14 January 2021

What is CVE-2021-21722?

An information leak vulnerability exists in the ZTE Smart STB, allowing attackers to exploit improper log verification. By taking advantage of this flaw, malicious actors can potentially access sensitive user data, posing risks of unauthorized information discovery and further attacks. It is crucial for users of the affected ZTE models to apply security updates and exercise caution.

Affected Version(s)

ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.