ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
2021-10-20T16:15:08.203
2024-11-21T05:48:55.583
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | mf971r_firmware | v1.0.0b05 | Yes |
Hardware | zte | mf971r | * | No |
Operating System | zte | mf971r_firmware | 1v1.0.0b06 | Yes |
Hardware | zte | mf971r | * | No |
Operating System | zte | mf971r_firmware | 2v1.0.0b03 | Yes |
Hardware | zte | mf971r | * | No |
Operating System | zte | mf971r_firmware | s2v1.0.0b03 | Yes |
Hardware | zte | mf971r | * | No |
Operating System | zte | mf971r_firmware | sv1.0.0b05 | Yes |
Hardware | zte | mf971r | * | No |