← Vulnerability feed

Vulnerability record · CVE-2021-21747 · published 20 October 2021

CVE-2021-21747: Zte mf971r firmware cross-site scripting vulnerability

Zte · Mf971r Firmware

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

6.1 CVSS 3.1 Medium EPSS 0.58% · top 54.5% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21747 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21748Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.8%9.8CVE-2021-21749Zte mf971r firmware out-of-bounds write vulnerabilityZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.EPSS 1.6%7.5CVE-2021-21744Zte mf971r firmware vulnerabilityZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of…EPSS 0.83%6.1CVE-2021-21746Zte mf971r firmware cross-site scripting vulnerabilityZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.EPSS 0.58%4.3CVE-2021-21743Zte mf971r firmware injection vulnerabilityZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information thr…EPSS 0.85%4.3CVE-2021-21745ZTE MF971R Referer authentication bypass via missing CSRF checkThe ZTE MF971R router trusts the Referer header for authorization decisions and does not verify CSRF tokens, so a crafted request can bypass authenti…EPSS 56%analysed6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21747), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.