Cross-Site Request Forgery Issue in ZTE ZXHN Routers
CVE-2021-21729

6.5MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
13 April 2021

What is CVE-2021-21729?

Certain ZTE ZXHN router models are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to insufficient verification of CSRF tokens on specific web pages. This security oversight could allow attackers to craft malicious requests, potentially leading to unauthorized actions on behalf of legitimate users. The affected models include ZXHN H168N V3.5.0_EG1T5, ZXHN H168N V2.5.5, and ZXHN H108N V2.5.5_BTMT1. It is essential for users of these routers to be aware of this vulnerability and apply recommended security measures to safeguard their systems.

Affected Version(s)

ZXHN H168N,ZXHN H108N V3.5.0_EG1T5_TE

ZXHN H168N,ZXHN H108N V2.5.5_BTMT1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.