← Vulnerability feed

Vulnerability record · CVE-2021-21745 · published 20 October 2021

CVE-2021-21745: ZTE MF971R Referer authentication bypass via missing CSRF check

Zte · Mf971r Firmware

The ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authentication checks. An attacker can trick a logged-in user into clicking a link that performs unauthorized configuration actions on the device.

4.3 CVSS 3.1 Medium EPSS 56% · top 1.0% CWE-352 · Cross-site request forgery
4.3CVSS 3.1 base score, v2 4.3
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS rates it medium (4.3) with limited integrity impact, but the high EPSS percentile and missing CSRF protection warrant prompt patching.

What it is

The ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authentication checks. An attacker can trick a logged-in user into clicking a link that performs unauthorized configuration actions on the device.

Impact

An attacker can perform unauthorized authorization operations on the router through the victim's authenticated session, with limited integrity impact and no direct confidentiality or availability loss per the CVSS vector.

Attack surface

Reached over the network via a request the victim is induced to click; no prior authentication is required by the attacker, but user interaction is required (UI:R) and the victim must have an active session on the device.

Exploitation

Not listed in CISA KEV and no public exploit references are provided; EPSS is high at 0.557 (99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.

What to do

  • Apply the vendor firmware update from the ZTE advisory (newsId=1019764) as the first action.
  • Do not browse other sites while logged into the MF971R management interface, and log out when finished.
  • Restrict management interface access to trusted networks and disable remote/WAN administration if supported.
  • Change default administrative credentials and avoid reusing them elsewhere.
  • Use a browser or extension that blocks cross-site requests to the router's management address.

Detection

  • Monitor router management logs for configuration or authorization changes preceded by requests with unexpected or external Referer headers.
  • Alert on management-interface requests originating from cross-site navigation patterns or unusual source IPs.
  • Review device audit logs for unauthorized configuration changes and correlate with user browsing activity.
  • Watch for repeated failed or anomalous authorization attempts against the MF971R web interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21745 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21748Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.8%9.8CVE-2021-21749Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.6%7.5CVE-2021-21744Zte mf971r firmware vulnerabilityZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of…EPSS 0.83%6.1CVE-2021-21746Zte mf971r firmware cross-site scripting vulnerabilityZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.EPSS 0.58%6.1CVE-2021-21747Zte mf971r firmware cross-site scripting vulnerabilityZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.EPSS 0.58%4.3CVE-2021-21743Zte mf971r firmware injection vulnerabilityZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information thr…EPSS 0.85%9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed8.1CVE-2008-4128Cisco IOS HTTP Administration CSRF allows arbitrary command executionThe HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws.…KEVEPSS 34%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21745), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.