Zte Mf971R Firmware vulnerabilities
7 known vulnerabilities affecting zte/mf971r_firmware.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2021-21745P2MEDIUMCVSS 4.3ExploitedPoCvv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21745 [MEDIUM] CWE-352 CVE-2021-21745: ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
nvd
CVE-2021-21748P3CRITICALCVSS 9.8vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21748 [CRITICAL] CWE-787 CVE-2021-21748: ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit th
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
nvd
CVE-2021-21749P3CRITICALCVSS 9.8vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21749 [CRITICAL] CWE-787 CVE-2021-21749: ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit th
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
nvd
CVE-2021-21744P3HIGHCVSS 7.5vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21744 [HIGH] CVE-2021-21744: ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulner
ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of the device to be disabled.
nvd
CVE-2021-21747P4MEDIUMCVSS 6.1vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21747 [MEDIUM] CWE-79 CVE-2021-21747: ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obta
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
nvd
CVE-2021-21746P4MEDIUMCVSS 6.1vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21746 [MEDIUM] CWE-79 CVE-2021-21746: ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obta
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
nvd
CVE-2021-21743P4MEDIUMCVSS 4.3vv1.0.0b05v1v1.0.0b06+4 more2021-10-20
CVE-2021-21743 [MEDIUM] CWE-74 CVE-2021-21743: ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability t
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
nvd