ZTE Conference Management System Command Execution Vulnerability

ZTE Conference Management System Command Execution Vulnerability

CVE-2021-21741 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

Learn more about our Web Application Penetration Testing UK.