CVE-2021-21726: Input Validation
Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219@NCPM-RELEASE2.40R1-20200914.set>
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21726?
CVE-2021-21726 is a vulnerability in ZTE products that allows an attacker with high privileges to cause a process exception by repeatedly inputting illegal parameters.
What ZTE products are affected by CVE-2021-21726?
ZTE products affected by CVE-2021-21726 include ZXONE 9700, ZXONE 8700, and ZXONE 19700.
What is the severity of CVE-2021-21726?
CVE-2021-21726 has a severity rating of low with a value of 2.3.
How can an attacker exploit CVE-2021-21726?
An attacker with high privileges can exploit CVE-2021-21726 by repeatedly inputting illegal parameters in the diagnostic function interface of the affected ZTE products.
Is there a fix available for CVE-2021-21726?
ZTE has released a security advisory detailing the vulnerability and recommending a software upgrade to address CVE-2021-21726.