Vulnerability Description
A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxhn Hs562 Firmware | 1.0.0.0b2.0000 |
| Zte | Zxhn Hs562 | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015964Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015964Vendor Advisory
FAQ
What is CVE-2021-21736?
CVE-2021-21736 is a vulnerability with a CVSS score of 7.2 (HIGH). A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have b...
How severe is CVE-2021-21736?
CVE-2021-21736 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21736?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxhn Hs562 Firmware, Zte Zxhn Hs562.