First published: Wed Oct 20 2021(Updated: )
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Mf971r Firmware | =v1.0.0b05 | |
ZTE MF971R | ||
Zte Mf971r Firmware | =1v1.0.0b06 | |
Zte Mf971r Firmware | =2v1.0.0b03 | |
Zte Mf971r Firmware | =s2v1.0.0b03 | |
Zte Mf971r Firmware | =sv1.0.0b05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21743 is a CRLF injection vulnerability in the ZTE MF971R product.
An attacker can exploit CVE-2021-21743 by modifying the HTTP response header information through a specially crafted HTTP request.
The severity of CVE-2021-21743 is medium with a CVSS score of 4.3.
The ZTE MF971R firmware versions v1.0.0b05, 1v1.0.0b06, 2v1.0.0b03, s2v1.0.0b03, sv1.0.0b05 are affected by CVE-2021-21743.
There is no information available on a specific fix for CVE-2021-21743 at the moment. It is recommended to follow the security advisory provided by ZTE.