CVE-2021-47740

7.5

KZ Broadband Technologies · JT3500V 4G LTE CPE

KZ Broadband Technologies 4G LTE CPE devices contain a session management vulnerability allowing attackers to reuse old session credentials due to improper expiration.

Executive summary

A session management flaw in multiple KZ Broadband Technologies LTE CPE models allows unauthenticated attackers to hijack sessions and potentially compromise device security.

Vulnerability

The device firmware exhibits insufficient session expiration (CWE-613), which enables the reuse of stale session tokens. This vulnerability is exploitable by an unauthenticated attacker, requiring no prior user interaction or valid credentials to potentially gain unauthorized access to the device management interface.

Business impact

Successful exploitation of this vulnerability can result in full unauthorized access to the CPE device management interface. This poses a significant risk to network integrity, as an attacker could modify device configurations, intercept traffic, or pivot into the internal network, leading to potential data breaches and service downtime. Given the CVSS score of 7.5, this is classified as a high-severity issue that warrants immediate administrative attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Contact the vendor or authorized service provider to verify the availability of updated firmware that addresses the session expiration flaw.

Proactive Monitoring: Review device access logs for suspicious login patterns or concurrent session activity that deviates from standard administrative behavior.

Compensating Controls: Implement strict access control lists (ACLs) to restrict management interface access to trusted, internal IP addresses only, and deploy a network firewall to block public exposure of the device management port.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept is linked via the Packet Storm Security reference.

Analyst recommendation

The presence of a public proof-of-concept combined with the ability for an unauthenticated attacker to manipulate session management makes this a high-priority risk for all organizations using the affected KZ Broadband Technologies CPE equipment. Security teams should prioritize isolating these devices from external networks immediately if updates are not yet available to prevent potential exploitation.

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.