PT-2021-14740 · Zte · Zte Zxhn H168N+1
Published
2021-04-13
·
Updated
2021-04-21
·
CVE-2021-21729
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE ZXHN H168N versions V2.5.5 through V3.5.0 EG1T5 TE
ZTE ZXHN H108N version V2.5.5 BTMT1
Description
The issue arises from the lack of CSRF random value verification on some pages, allowing attackers to perform unauthorized operations by constructing malicious messages. This can lead to illegal authorization.
Recommendations
For ZTE ZXHN H168N versions V2.5.5 through V3.5.0 EG1T5 TE, consider implementing CSRF random value verification to prevent unauthorized operations.
For ZTE ZXHN H108N version V2.5.5 BTMT1, consider implementing CSRF random value verification to prevent unauthorized operations.
As a temporary workaround, consider restricting access to sensitive pages that lack CSRF protection to minimize the risk of exploitation.
Fix
Use of Insufficiently Random Values
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zte Zxhn H108N
Zte Zxhn H168N