← back
CVE-2021-47740

KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability

CVSS 6.9 MEDIUMEPSS 0.4%CWE-613
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
31 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →