216.73.217.22

CVE-2021-4471

· Published 14/11/2025 23:15 · Modified 18/11/2025 14:06

Labels: CVE-2021-4471 2025-11-14CVE-2021-4471CWE-538[email protected]

Essential information

Published
14/11/2025 23:15
Modified
18/11/2025 14:06
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References