CVE-2021-21722

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxv10_b860a_firmware:v2.1-t_v0032.1.1.04_jiangsutelecom:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxv10_b860a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:48

Type Values Removed Values Added
References () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 - Vendor Advisory () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 - Vendor Advisory

Information

Published : 2021-01-14 16:15

Updated : 2024-11-21 05:48


NVD link : CVE-2021-21722

Mitre link : CVE-2021-21722

CVE.ORG link : CVE-2021-21722


JSON object : View

Products Affected

zte

  • zxv10_b860a
  • zxv10_b860a_firmware
CWE
CWE-532

Insertion of Sensitive Information into Log File