4.3

CVE-2021-21745

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZteMf971r Firmware Versionv1.0.0b05
   ZteMf971r
ZteMf971r Firmware Version1v1.0.0b06
   ZteMf971r
ZteMf971r Firmware Version2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versions2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versionsv1.0.0b05
   ZteMf971r
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 40.59% 0.972
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.