漏洞描述
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.talosintelligence.comhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1317↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-21745↗support.zte.com.cnhttps://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗