Reflective XSS Vulnerability in ZTE MF971R Product
CVE-2021-21746

6.1MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 October 2021

What is CVE-2021-21746?

The ZTE MF971R product is affected by a reflective Cross-Site Scripting (XSS) vulnerability, allowing attackers to exploit this flaw to extract cookie information. By crafting a malicious URL that leverages this vulnerability, an attacker can potentially gain unauthorized access to sensitive user data stored in cookies, posing significant risks to user privacy and security.

Affected Version(s)

MF971R BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.