Information Leak Vulnerability in ZXHN H168N by ZTE
CVE-2021-21735

6.5MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
10 June 2021

What is CVE-2021-21735?

The ZXHN H168N product by ZTE is susceptible to an information leak due to inadequate permission configurations. This vulnerability enables an attacker with standard user credentials to retrieve sensitive user information through the wizard page without the need for authentication. Users of all versions up to V3.5.0_EG1T4_TE are at risk, highlighting the necessity for immediate action to secure these devices.

Affected Version(s)

ZXHN H168N All versions up to V3.5.0_EG1T4_TE

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.