A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.
References
Link | Resource |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1014324 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-01-14 08:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-21722
Mitre link : CVE-2021-21722
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
zte
- zxv10_b860a
- zxv10_b860a_firmware