CVE-2021-21743: CRLF Injection
Published Oct 20, 2021
·Updated
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
Affected Software
6 affected components
ZTE Mf971r Firmware=v1.0.0b05
ZTE MF971R
ZTE Mf971r Firmware=1v1.0.0b06
ZTE Mf971r Firmware=2v1.0.0b03
ZTE Mf971r Firmware=s2v1.0.0b03
ZTE Mf971r Firmware=sv1.0.0b05
Event History
Oct 20, 2021
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-21743?
CVE-2021-21743 is a CRLF injection vulnerability in the ZTE MF971R product.
2
How can an attacker exploit CVE-2021-21743?
An attacker can exploit CVE-2021-21743 by modifying the HTTP response header information through a specially crafted HTTP request.
3
What is the severity of CVE-2021-21743?
The severity of CVE-2021-21743 is medium with a CVSS score of 4.3.
4
Which software versions of ZTE MF971R are affected by CVE-2021-21743?
The ZTE MF971R firmware versions v1.0.0b05, 1v1.0.0b06, 2v1.0.0b03, s2v1.0.0b03, sv1.0.0b05 are affected by CVE-2021-21743.
5
How can CVE-2021-21743 be fixed?
There is no information available on a specific fix for CVE-2021-21743 at the moment. It is recommended to follow the security advisory provided by ZTE.