PT-2021-14740 · Zte · Zte Zxhn H168N+1

Published

2021-04-13

·

Updated

2021-04-21

·

CVE-2021-21729

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZTE ZXHN H168N versions V2.5.5 through V3.5.0 EG1T5 TE ZTE ZXHN H108N version V2.5.5 BTMT1
Description The issue arises from the lack of CSRF random value verification on some pages, allowing attackers to perform unauthorized operations by constructing malicious messages. This can lead to illegal authorization.
Recommendations For ZTE ZXHN H168N versions V2.5.5 through V3.5.0 EG1T5 TE, consider implementing CSRF random value verification to prevent unauthorized operations. For ZTE ZXHN H108N version V2.5.5 BTMT1, consider implementing CSRF random value verification to prevent unauthorized operations. As a temporary workaround, consider restricting access to sensitive pages that lack CSRF protection to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21729

Affected Products

Zte Zxhn H108N
Zte Zxhn H168N