VYPR
Unrated severityNVD Advisory· Published Aug 5, 2021· Updated Aug 3, 2024

CVE-2021-21738

CVE-2021-21738

Description

ZTE's big video business platform (ZXIPTV-EAS_PV5.06.04.09) has two reflective XSS flaws due to insufficient input validation, allowing script injection via parameter tampering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ZTE's big video business platform (ZXIPTV-EAS_PV5.06.04.09) has two reflective XSS flaws due to insufficient input validation, allowing script injection via parameter tampering.

Vulnerability

ZTE's big video business platform, specifically the ZXIPTV-EAS_PV5.06.04.09 version, contains two reflective cross-site scripting (XSS) vulnerabilities [1]. The flaws arise from insufficient input verification, enabling an attacker to inject malicious scripts by tampering with parameters in HTTP requests [1].

Exploitation

An attacker can craft a malicious URL with tampered parameters and trick a valid user into clicking it, leading to script execution in the user's browser [1]. The attack requires no special privileges and does not require user interaction beyond the initial click, as per the CVSS vector (AV:L/AC:H/PR:N/UI:N) [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially affecting the operations of valid users [1]. The CVSS score indicates a low availability impact, with no direct confidentiality or integrity compromise [1].

Mitigation

ZTE has released a fixed version: ZXIPTV-EAS-PV7.01.05.01 [1]. Users should upgrade to this version to remediate the vulnerabilities. No workarounds are documented in the available reference [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • ZTE/big video business platformdescription
  • Zte/ZXIPTVllm-fuzzy
    Range: = ZXIPTV-EAS_PV5.06.04.09

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.