CVE-2021-21741

EUVD-2021-8913
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
ztezxv10_m910_firmware
1.2.16.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.19.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.20.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.21.01.04:p01
𝑥
= Vulnerable software versions