Stack-Based Buffer Overflow in ZTE MF971R Product
CVE-2021-21749

9.8CRITICAL

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
20 October 2021

What is CVE-2021-21749?

The ZTE MF971R device is susceptible to two stack-based buffer overflow vulnerabilities. These flaws could allow an attacker to exploit the system, potentially leading to the execution of arbitrary code. This situation underscores the importance of timely updates and security management practices to mitigate risks effectively.

Affected Version(s)

MF971R BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.