A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.
References
Link | Resource |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 | Vendor Advisory |
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 - Vendor Advisory |
Information
Published : 2021-01-14 16:15
Updated : 2024-11-21 05:48
NVD link : CVE-2021-21722
Mitre link : CVE-2021-21722
CVE.ORG link : CVE-2021-21722
JSON object : View
Products Affected
zte
- zxv10_b860a
- zxv10_b860a_firmware
CWE
CWE-532
Insertion of Sensitive Information into Log File