CVE-2021-21741

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ztezxv10_m910_firmware
1.2.16.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.19.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.20.01u01.01:u01.01
ztezxv10_m910_firmware
1.2.21.01.04:p01
𝑥
= Vulnerable software versions