VulnerabilityModified
CVE-2021-21729
Some ZTE products have CSRF vulnerability.
MEDIUM 6.5EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330, CWE-352
- Affected
- zte/zxhn h168n firmware · zte/zxhn h108n firmware
- Source
- psirt@zte.com.cn
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.