{"api_version":"1","generated_at":"2026-07-23T15:13:10+00:00","cve":"CVE-2021-21740","urls":{"html":"https://cve.report/CVE-2021-21740","api":"https://cve.report/api/cve/CVE-2021-21740.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21740","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21740"},"summary":{"title":"CVE-2021-21740","description":"There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.","state":"PUBLIC","assigner":"psirt@zte.com.cn","published_at":"2021-08-09 16:15:00","updated_at":"2021-08-17 14:03:00"},"problem_types":["CWE-59"],"metrics":[],"references":[{"url":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244","name":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244","refsource":"MISC","tags":[],"title":"Security Bulletin Details","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21740","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21740","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21740","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zte","cpe5":"zxhn_h2640","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"21740","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zte","cpe5":"zxhn_h2640_firmware","cpe6":"10.0.0c6_ty","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-21740","ASSIGNER":"psirt@zte.com.cn","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"ZXHN H2640","version":{"version_data":[{"version_value":"V10.0.0C6_TY"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"information leak"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244","url":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017244"}]},"description":{"description_data":[{"lang":"eng","value":"There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak."}]}},"nvd":{"publishedDate":"2021-08-09 16:15:00","lastModifiedDate":"2021-08-17 14:03:00","problem_types":["CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.4,"baseSeverity":"LOW"},"exploitabilityScore":0.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:zte:zxhn_h2640_firmware:10.0.0c6_ty:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:zte:zxhn_h2640:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21740","Ordinal":"196429","Title":"CVE-2021-21740","CVE":"CVE-2021-21740","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21740","Ordinal":"1","NoteData":"There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21740","Ordinal":"2","NoteData":"2021-08-09","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21740","Ordinal":"3","NoteData":"2021-08-09","Type":"Other","Title":"Modified"}]}}}