There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244 | Vendor Advisory |
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244 - Vendor Advisory |
Information
Published : 2021-08-09 16:15
Updated : 2024-11-21 05:48
NVD link : CVE-2021-21740
Mitre link : CVE-2021-21740
CVE.ORG link : CVE-2021-21740
JSON object : View
Products Affected
zte
- zxhn_h2640_firmware
- zxhn_h2640
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')