VulnerabilityModified
CVE-2021-21740
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product.
LOW 2.4EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.
- CVSS 3.1
- 2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- zte/zxhn h2640 firmware
- Source
- psirt@zte.com.cn
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.