HIGH · 7.2

CVE-2021-21736

A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have b...

Vulnerability Description

A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteZxhn Hs562 Firmware1.0.0.0b2.0000
ZteZxhn Hs562-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21736?

CVE-2021-21736 is a vulnerability with a CVSS score of 7.2 (HIGH). A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have b...

How severe is CVE-2021-21736?

CVE-2021-21736 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21736?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxhn Hs562 Firmware, Zte Zxhn Hs562.