Vulnerability Description
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10 B860H V5.0, V83011303.0010, V83011303.0016
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxv10 B860H V5.0 Firmware | v83011303.0010 |
| Zte | Zxv10 B860H V5.0 | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1016004Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1016004Vendor Advisory
FAQ
What is CVE-2021-21737?
CVE-2021-21737 is a vulnerability with a CVSS score of 7.5 (HIGH). A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the...
How severe is CVE-2021-21737?
CVE-2021-21737 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21737?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxv10 B860H V5.0 Firmware, Zte Zxv10 B860H V5.0.