CVE-2021-21731

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/04/2021
Last modified:
28/01/2025

Description

A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:* 6.03.04 (excluding)
cpe:2.3:a:zte:zxcloud_irai:-:*:*:*:*:*:*:*