CVE-2021-21729: CSRF
Published Apr 13, 2021
·Updated
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0EG1T5TE, V2.5.5, ZXHN H108N V2.5.5BTMT1
Affected Software
4 affected components
ZTE Zxhn H168n Firmware=3.5.0_eg1t5_te
ZTE ZXHN H168N
ZTE Zxhn H108n Firmware=2.5.5_btmt1
ZTE ZXHN H108N
Event History
Apr 13, 2021
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF vulnerability in ZTE products?
The vulnerability ID for this CSRF vulnerability in ZTE products is CVE-2021-21729.
2
What is the severity of CVE-2021-21729?
The severity of CVE-2021-21729 is medium with a CVSS score of 6.5.
3
Which ZTE products are affected by CVE-2021-21729?
ZXHN H168N V3.5.0_EG1T5_TE and ZXHN H108N V2.5.5_BTMT1 are affected by CVE-2021-21729.
4
How could attackers exploit CVE-2021-21729?
Attackers could perform illegal authorization operations by constructing messages due to the CSRF vulnerability in ZTE products.
5
Is there a fix available for CVE-2021-21729?
Please refer to the ZTE support website for information on fixes for CVE-2021-21729.