First published: Thu Aug 05 2021(Updated: )
A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system authentication and detection, thus affecting signal transmission. This affects: <ZXCTN 6120H><V5.10.00B24>
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Zxctn 6120h Firmware | =5.10.00b24 | |
Zte Zxctn 6120h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21739.
The severity of CVE-2021-21739 is medium with a CVSS score of 4.6.
ZTE ZXCTN 6120H Firmware version 5.10.00b24 is affected by CVE-2021-21739.
An attacker can exploit CVE-2021-21739 by replacing an authenticated optical module with an unauthenticated one, bypassing system authentication and detection.
ZTE ZXCTN 6120H is not vulnerable to CVE-2021-21739.