Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21736


A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E


Published

2021-06-10T12:15:08.490

Last Modified

2024-11-21T05:48:54.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

8.5

Weaknesses
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte zxhn_hs562_firmware 1.0.0.0b2.0000 Yes
Operating System zte zxhn_hs562_firmware 1.0.0.0b3.0000 Yes
Hardware zte zxhn_hs562 - No

References