Vulnerability Description
Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set>
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxone 9700 Firmware | 1.40.021.021cp049 |
| Zte | Zxone 9700 | - |
| Zte | Zxone 8700 Firmware | 1.40.021.021cp049 |
| Zte | Zxone 8700 | - |
| Zte | Zxone 19700 Firmware | 1.0p02b219_\@ncpm-release_2.40r1-20200914.set |
| Zte | Zxone 19700 | - |
Related Weaknesses (CWE)
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014664Vendor Advisory
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014664Vendor Advisory
FAQ
What is CVE-2021-21726?
CVE-2021-21726 is a vulnerability with a CVSS score of 2.3 (LOW). Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges ca...
How severe is CVE-2021-21726?
CVE-2021-21726 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21726?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxone 9700 Firmware, Zte Zxone 9700, Zte Zxone 8700 Firmware, Zte Zxone 8700, Zte Zxone 19700 Firmware.