PT-2025-54422 · Zbl · Zbl Epon Onu Broadband Router

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2021-47741

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZBL EPON ONU Broadband Router version V100R001
Description A privilege escalation issue exists in ZBL EPON ONU Broadband Router version V100R001. Limited administrative users can increase their access level by sending requests to configuration endpoints. Exploitation involves accessing the configuration backup or password page to reveal the super user password, granting additional privileged functionalities. The affected API endpoints include configuration backup and password pages. The vulnerable action involves sending requests to these endpoints.
Recommendations Restrict access to the configuration backup page. Restrict access to the password page.

Exploit

Fix

LPE

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-47741

Affected Products

Zbl Epon Onu Broadband Router