6.1

CVE-2021-21746

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

Data is provided by the National Vulnerability Database (NVD)
ZteMf971r Firmware Versionv1.0.0b05
   ZteMf971r
ZteMf971r Firmware Version1v1.0.0b06
   ZteMf971r
ZteMf971r Firmware Version2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versions2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versionsv1.0.0b05
   ZteMf971r
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.644
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.