First published: Mon Aug 09 2021(Updated: )
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Zxhn H2640 Firmware | =10.0.0c6_ty | |
Zte Zxhn H2640 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21740 is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product.
An attacker can insert a USB disk with a symbolic link into the residential gateway, allowing them to access unauthorized directory information through the symbolic link.
CVE-2021-21740 has a severity score of 2.4, which is considered low.
ZTE ZXHN H2640 Firmware version 10.0.0c6_ty is affected by CVE-2021-21740.
Update the ZTE ZXHN H2640 Firmware to version 10.0.0c6_ty or higher to fix CVE-2021-21740.