{"api_version":"1","generated_at":"2026-07-24T01:47:47+00:00","cve":"CVE-2021-21751","urls":{"html":"https://cve.report/CVE-2021-21751","api":"https://cve.report/api/cve/CVE-2021-21751.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21751","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21751"},"summary":{"title":"CVE-2021-21751","description":"ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.","state":"PUBLIC","assigner":"psirt@zte.com.cn","published_at":"2021-12-27 19:15:00","updated_at":"2023-08-08 14:22:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884","name":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884","refsource":"MISC","tags":[],"title":"Security Bulletin Details","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21751","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21751","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21751","vulnerable":"1","versionEndIncluding":"3.01.01.04","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zte","cpe5":"zxin10_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-21751","ASSIGNER":"psirt@zte.com.cn","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"ZXIN10 CMS","version":{"version_data":[{"version_value":"All versions up to ZXOMS-BIGDATA-IOPSWEBV3.01.01.04"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"input verification"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884","url":"https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884"}]},"description":{"description_data":[{"lang":"eng","value":"ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception."}]}},"nvd":{"publishedDate":"2021-12-27 19:15:00","lastModifiedDate":"2023-08-08 14:22:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zte:zxin10_cms:*:*:*:*:*:*:*:*","versionEndIncluding":"3.01.01.04","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21751","Ordinal":"196440","Title":"CVE-2021-21751","CVE":"CVE-2021-21751","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21751","Ordinal":"1","NoteData":"ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21751","Ordinal":"2","NoteData":"2021-12-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21751","Ordinal":"3","NoteData":"2021-12-27","Type":"Other","Title":"Modified"}]}}}