CVE-2021-21741

A conference management system of ZTE is impacted by a command execution vulnerability. Since the soapmonitor's java object service is enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending a deserialized payload to port 5001.
Configurations

Configuration 1


Information

Published : 2021-08-30 06:15

Updated : 2021-09-07 02:04


NVD link : CVE-2021-21741

Mitre link : CVE-2021-21741

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data