ZeroHour

CVE-2021-21741

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

Vendors
zte
Products
zxv10 m910 firmware
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.