Vulnerability Details CVE-2021-21731
A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.8%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.8
Products affected by CVE-2021-21731
-
cpe:2.3:a:zte:zxcloud_irai:-
-
cpe:2.3:a:zte:zxcloud_irai:5.01.05
-
cpe:2.3:a:zte:zxcloud_irai:5.01.06