CVE-2021-21746: XSS
Published Oct 20, 2021
·Updated
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
Affected Software
6 affected components
ZTE Mf971r Firmware=v1.0.0b05
ZTE MF971R
ZTE Mf971r Firmware=1v1.0.0b06
ZTE Mf971r Firmware=2v1.0.0b03
ZTE Mf971r Firmware=s2v1.0.0b03
ZTE Mf971r Firmware=sv1.0.0b05
Event History
Oct 20, 2021
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-21746?
CVE-2021-21746 is a reflective XSS vulnerability in the ZTE MF971R product.
2
How can an attacker exploit CVE-2021-21746?
An attacker can exploit CVE-2021-21746 to obtain cookie information.
3
What is the severity of CVE-2021-21746?
The severity of CVE-2021-21746 is medium with a CVSS score of 6.1.
4
Which software versions are affected by CVE-2021-21746?
The ZTE MF971R firmware versions v1.0.0b05, 1v1.0.0b06, 2v1.0.0b03, s2v1.0.0b03, and sv1.0.0b05 are affected by CVE-2021-21746.
5
Is there a fix available for CVE-2021-21746?
Yes, ZTE has provided a fix for CVE-2021-21746. Please refer to the reference link for more details.