← Vulnerability feed

Vulnerability record · CVE-2021-21743 · published 20 October 2021

CVE-2021-21743: Zte mf971r firmware injection vulnerability

Zte · Mf971r Firmware

ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.

4.3 CVSS 3.1 Medium EPSS 0.85% · top 43.5% CWE-74 · Injection
4.3CVSS 3.1 base score, v2 4.3
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21743 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21748Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.8%9.8CVE-2021-21749Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.6%7.5CVE-2021-21744Zte mf971r firmware vulnerabilityZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of…EPSS 0.83%6.1CVE-2021-21746Zte mf971r firmware cross-site scripting vulnerabilityZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.EPSS 0.58%6.1CVE-2021-21747Zte mf971r firmware cross-site scripting vulnerabilityZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.EPSS 0.58%4.3CVE-2021-21745ZTE MF971R Referer authentication bypass via missing CSRF checkThe ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authenti…EPSS 56%analysed10.0CVE-2025-20337Cisco ISE API input validation flaw allows unauthenticated root RCECisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary c…KEVEPSS 68%analysed10.0CVE-2025-20281Cisco ISE API unauthenticated remote code executionCisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating s…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21743), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.