{ "schema_version": "1.4.0", "id": "GHSA-j56v-m9w9-5r65", "modified": "2022-05-24T19:04:55Z", "published": "2022-05-24T19:04:55Z", "aliases": [ "CVE-2021-21736" ], "details": "A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21736" }, { "type": "WEB", "url": "https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015964" } ], "database_specific": { "cwe_ids": [ "CWE-276" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-06-10T12:15:00Z" } }