Lucene search

K
cveMitreCVE-2014-2321
HistoryMar 11, 2014 - 1:01 p.m.

CVE-2014-2321

2014-03-1113:01:19
CWE-264
mitre
web.nvd.nist.gov
140
In Wild
zte
f460
f660
cable modems
vulnerability
remote access
administrative access

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.952

Percentile

99.4%

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using β€œset TelnetCfg” commands to enable a TELNET service with specified credentials.

Affected configurations

Nvd
Node
ztef460Match-
OR
ztef660Match-
VendorProductVersionCPE
ztef460-cpe:2.3:h:zte:f460:-:*:*:*:*:*:*:*
ztef660-cpe:2.3:h:zte:f660:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.952

Percentile

99.4%