CVE-2021-21741

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
zteCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
ztezxv10_m910_firmware
1.2.16.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.19.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.20.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.21.01.04:p01
𝑥
= Vulnerable software versions