2.4
CVE-2021-21740
- EPSS 0.05%
- Veröffentlicht 09.08.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:54
- Quelle psirt@zte.com.cn
- CVE-Watchlists
- Unerledigt
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Zxhn H2640 Firmware Version10.0.0c6_ty
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.122 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.4 | 0.9 | 1.4 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.