CVE-2021-47740
7.5KZ Broadband Technologies · JT3500V 4G LTE CPE
KZ Broadband Technologies 4G LTE CPE devices contain a session management vulnerability allowing attackers to reuse old session credentials due to improper expiration.
Executive summary
A session management flaw in multiple KZ Broadband Technologies LTE CPE models allows unauthenticated attackers to hijack sessions and potentially compromise device security.
Vulnerability
The device firmware exhibits insufficient session expiration (CWE-613), which enables the reuse of stale session tokens. This vulnerability is exploitable by an unauthenticated attacker, requiring no prior user interaction or valid credentials to potentially gain unauthorized access to the device management interface.
Business impact
Successful exploitation of this vulnerability can result in full unauthorized access to the CPE device management interface. This poses a significant risk to network integrity, as an attacker could modify device configurations, intercept traffic, or pivot into the internal network, leading to potential data breaches and service downtime. Given the CVSS score of 7.5, this is classified as a high-severity issue that warrants immediate administrative attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Contact the vendor or authorized service provider to verify the availability of updated firmware that addresses the session expiration flaw.
Proactive Monitoring: Review device access logs for suspicious login patterns or concurrent session activity that deviates from standard administrative behavior.
Compensating Controls: Implement strict access control lists (ACLs) to restrict management interface access to trusted, internal IP addresses only, and deploy a network firewall to block public exposure of the device management port.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is linked via the Packet Storm Security reference.
Analyst recommendation
The presence of a public proof-of-concept combined with the ability for an unauthenticated attacker to manipulate session management makes this a high-priority risk for all organizations using the affected KZ Broadband Technologies CPE equipment. Security teams should prioritize isolating these devices from external networks immediately if updates are not yet available to prevent potential exploitation.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2021-5646) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- IBM X-Force Vulnerability Exchange Entry Vulnerability database entry
- KZ TECH Vendor Homepage
- JATON TEC Homepage
- Neotel Vendor Homepage
- VulnCheck Advisory: KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability Third-party advisory