Referer Authentication Bypass in ZTE MF971R
CVE-2021-21745 
4.3MEDIUM
What is CVE-2021-21745?
The ZTE MF971R device is susceptible to a referer authentication bypass vulnerability. This issue allows attackers to execute unauthorized actions by persuading users to click on malicious links, thereby sending crafted requests to the affected system without requiring CSRF validation. As a result, attackers can perform operations that should be restricted, leading to potential compromise of user data and network security.
Affected Version(s)
MF971R BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05
References
EPSS Score
40% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
 Low
Availability:
 None
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 Required
Scope:
 Unchanged
Timeline
- Vulnerability published 
- Vulnerability Reserved 
