« Volver al listado

CVE-2021-21749

Estado: ModificadaCrítica (9.8)—

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21749",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@zte.com.cn",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "MF971R",
          "versions": [
            {
              "status": "affected",
              "version": "BD_ZTE_MF971RV1.0.0B05, BD_PLKPLMF971R1V1.0.0B06, BD_MF971R2V1.0.0B03, BD_ZTE_MF971RS2V1.0.0B03, BD_ZTE_MF971RSV1.0.0B05"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-10-20T16:15:08.293",
  "references": [
    {
      "url": "https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@zte.com.cn"
    },
    {
      "url": "https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "El producto ZTE MF971R presenta dos vulnerabilidades de desbordamiento de búfer en la región stack de la memoria. Un atacante podría explotar las vulnerabilidades para ejecutar código arbitrario"
    }
  ],
  "lastModified": "2026-06-17T03:36:05.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zte:mf971r_firmware:v1.0.0b05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72A4F659-C656-47D6-B38E-5BA8E73DCD30"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zte:mf971r:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A7F54F4-E324-4D1E-839E-677396BAFE49"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zte:mf971r_firmware:1v1.0.0b06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35FA4400-636F-48E7-AF1E-9416D9E9386F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zte:mf971r:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A7F54F4-E324-4D1E-839E-677396BAFE49"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zte:mf971r_firmware:2v1.0.0b03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "252BBFAA-0053-441A-8F20-A737EF573355"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zte:mf971r:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A7F54F4-E324-4D1E-839E-677396BAFE49"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zte:mf971r_firmware:s2v1.0.0b03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B066F08-DDC4-4868-8FD2-620E46660B64"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zte:mf971r:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A7F54F4-E324-4D1E-839E-677396BAFE49"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zte:mf971r_firmware:sv1.0.0b05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAA1BD70-DC47-4B81-A906-3FD76E593F75"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zte:mf971r:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A7F54F4-E324-4D1E-839E-677396BAFE49"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@zte.com.cn"
}