VYPR
Unrated severityNVD Advisory· Published Mar 12, 2021· Updated Aug 3, 2024

CVE-2021-21726

CVE-2021-21726

Description

ZTE ZXONE products have an input verification vulnerability in the diagnostic interface allowing high-privilege attackers to cause process exceptions via repeated illegal parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ZTE ZXONE products have an input verification vulnerability in the diagnostic interface allowing high-privilege attackers to cause process exceptions via repeated illegal parameters.

Vulnerability

An input verification vulnerability exists in the diagnostic function interface of certain ZTE ZXONE products. The flaw stems from insufficient validation of user-supplied parameters, enabling an attacker with high privileges to trigger process exceptions by repeatedly sending illegal inputs. Affected products and versions include ZXONE 9700 and ZXONE 8700 running V1.40.021.021CP049, and ZXONE 19700 running V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set [1].

Exploitation

An attacker must already possess high privileges on the affected device. Exploitation involves repeatedly inputting illegal parameters into the diagnostic interface. No user interaction or network access beyond the local management interface is required; the attack vector is local with high attack complexity due to the privilege requirement [1].

Impact

Successful exploitation leads to a process exception, resulting in a denial of service condition affecting availability. The CVSS v3.1 base score is 1.9 (Low), with no impact on confidentiality or integrity [1]. The scope remains unchanged.

Mitigation

ZTE has released fixed versions: for ZXONE 9700 and 8700, upgrade to V1.40.040.100_M2SNPE; for ZXONE 19700, upgrade to V1.0P02B224_@NCPM-RELEASE_2.40R1-20201208.set or V1.0P02B224C16_@NCPM.set [1]. No workarounds are documented. The vulnerability was discovered internally and disclosed on March 10, 2021.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • ZTE/ZXONE 9700 , ZXONE 8700, ZXONE 19700description
  • Zte/ZXONE 9700llm-create
    Range: = V1.40.021.021CP049
  • Zte/ZXONE 8700llm-create
    Range: = V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set
  • Zte/ZXONE 19700llm-create
    Range: = V1.40.021.021CP049

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.