9.8

CVE-2021-21749

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
ZteMf971r Firmware Versionv1.0.0b05
   ZteMf971r
ZteMf971r Firmware Version1v1.0.0b06
   ZteMf971r
ZteMf971r Firmware Version2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versions2v1.0.0b03
   ZteMf971r
ZteMf971r Firmware Versionsv1.0.0b05
   ZteMf971r
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.3% 0.786
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.