Referer Authentication Bypass in ZTE MF971R
CVE-2021-21745

4.3MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 October 2021

What is CVE-2021-21745?

The ZTE MF971R device is susceptible to a referer authentication bypass vulnerability. This issue allows attackers to execute unauthorized actions by persuading users to click on malicious links, thereby sending crafted requests to the affected system without requiring CSRF validation. As a result, attackers can perform operations that should be restricted, leading to potential compromise of user data and network security.

Affected Version(s)

MF971R BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05

References

EPSS Score

40% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.