Vulnerability record · CVE-2021-21745 · published 20 October 2021
CVE-2021-21745: ZTE MF971R Referer authentication bypass via missing CSRF check
Zte · Mf971r Firmware
The ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authentication checks. An attacker can trick a logged-in user into clicking a link that performs unauthorized configuration actions on the device.
Description
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (4.3) with limited integrity impact, but the high EPSS percentile and missing CSRF protection warrant prompt patching.
What it is
The ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authentication checks. An attacker can trick a logged-in user into clicking a link that performs unauthorized configuration actions on the device.
Impact
An attacker can perform unauthorized authorization operations on the router through the victim's authenticated session, with limited integrity impact and no direct confidentiality or availability loss per the CVSS vector.
Attack surface
Reached over the network via a request the victim is induced to click; no prior authentication is required by the attacker, but user interaction is required (UI:R) and the victim must have an active session on the device.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is high at 0.557 (99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Apply the vendor firmware update from the ZTE advisory (newsId=1019764) as the first action.
- Do not browse other sites while logged into the MF971R management interface, and log out when finished.
- Restrict management interface access to trusted networks and disable remote/WAN administration if supported.
- Change default administrative credentials and avoid reusing them elsewhere.
- Use a browser or extension that blocks cross-site requests to the router's management address.
Detection
- Monitor router management logs for configuration or authorization changes preceded by requests with unexpected or external Referer headers.
- Alert on management-interface requests originating from cross-site navigation patterns or unusual source IPs.
- Review device audit logs for unauthorized configuration changes and correlate with user browsing activity.
- Watch for repeated failed or anomalous authorization attempts against the MF971R web interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764 | Vendor Advisory |
| https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764 | Vendor Advisory |
Track CVE-2021-21745 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21745), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.