CVE-2021-21745: CSRF
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21745?
CVE-2021-21745 is a vulnerability in the ZTE MF971R product that allows an attacker to bypass Referer authentication.
How does CVE-2021-21745 work?
CVE-2021-21745 works by exploiting a lack of CSRF verification, allowing an attacker to perform unauthorized operations by tricking the user into clicking on a malicious request.
What is the severity of CVE-2021-21745?
CVE-2021-21745 has a severity rating of medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2021-21745?
The ZTE MF971R firmware versions v1.0.0b05, 1v1.0.0b06, 2v1.0.0b03, s2v1.0.0b03, and sv1.0.0b05 are affected by CVE-2021-21745.
How can I fix CVE-2021-21745?
To fix CVE-2021-21745, ZTE has released a security patch. Please refer to the ZTE Support page at the provided link for more information.