CVE-2021-21722

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxv10_b860a_firmware:v2.1-t_v0032.1.1.04_jiangsutelecom:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxv10_b860a:-:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-200 CWE-532

21 Jan 2021, 21:07

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 4.4
CPE cpe:2.3:o:zte:zxv10_b860a_firmware:v2.1-t_v0032.1.1.04_jiangsutelecom:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxv10_b860a:-:*:*:*:*:*:*:*
References (MISC) http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 - (MISC) http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 - Vendor Advisory

14 Jan 2021, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-14 16:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-21722

Mitre link : CVE-2021-21722

CVE.ORG link : CVE-2021-21722


JSON object : View

Products Affected

zte

  • zxv10_b860a_firmware
  • zxv10_b860a
CWE
CWE-532

Insertion of Sensitive Information into Log File