KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability
Vulnerability Description
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47740
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5646.php
- https://packetstormsecurity.com/files/161892/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/198471
- http://www.kzbtech.com/
- https://www.jatontech.com/
- https://neotel.mk/
- https://www.vulncheck.com/advisories/kztech-jtv-g-lte-cpe-insufficient-session-expiration-vulnerability
Affected Vendor
KZ Broadband Technologies, Ltd.
View all reports →