Reflective XSS Vulnerability in ZTE MF971R Router
CVE-2021-21747

6.1MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 October 2021

What is CVE-2021-21747?

The ZTE MF971R router is susceptible to a reflective cross-site scripting (XSS) vulnerability, which can be exploited by attackers to manipulate web requests. Through this vulnerability, an attacker may gain unauthorized access to sensitive cookie data, potentially compromising user sessions and personal information. This flaw underscores the need for users to implement security measures to safeguard against exploitation.

Affected Version(s)

MF971R BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.