CVE-2021-21735
Last modified
CVE-2021-21735 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0_EG1T4_TE.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxhn H168n Firmware | <= 3.5.0_eg1t4_te |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21735?
How severe is CVE-2021-21735?
How do I fix CVE-2021-21735?
Are you affected by CVE-2021-21735?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
