Home

Description

KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.

PUBLISHED Reserved 2025-12-23 | Published 2025-12-31 | Updated 2026-01-02 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

Insufficient Session Expiration

Product status

2.0.1B1064
affected

2.0.1B1047
affected

2.0.0B3210
affected

2.0.0B3042
affected

2.0.0B3037
affected

2.0.0B2996
affected

2.0.0B2988
affected

2.0.0B1092
affected

2.0.0B1085
affected

2.0.0B1060
affected

2.0.0B981
affected

2.0.0B946
affected

2.0.0B21
affected

2.0.0B14
affected

2.0.0B04
affected

2.0.0B01
affected

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5646.php (Zero Science Lab Disclosure (ZSL-2021-5646)) third-party-advisory

packetstormsecurity.com/files/161892/ (Packet Storm Security Exploit Entry) exploit

exchange.xforce.ibmcloud.com/vulnerabilities/198471 (IBM X-Force Vulnerability Exchange Entry) vdb-entry

www.kzbtech.com/ (KZ TECH Vendor Homepage) product

www.jatontech.com/ (JATON TEC Homepage) product

neotel.mk/ (Neotel Vendor Homepage) product

www.vulncheck.com/...icient-session-expiration-vulnerability (VulnCheck Advisory: KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability) third-party-advisory

cve.org (CVE-2021-47740)

nvd.nist.gov (CVE-2021-47740)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.