← Back to CVE List
CVE-2014-9118NVD
Vulnerability Summary
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
CVSS v3.0 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
External References
- http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html
- http://seclists.org/fulldisclosure/2015/Oct/57
- http://www.securityfocus.com/archive/1/536663/100/0/threaded
- https://www.exploit-db.com/exploits/38453/
- http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html
- http://seclists.org/fulldisclosure/2015/Oct/57
- http://www.securityfocus.com/archive/1/536663/100/0/threaded
- https://www.exploit-db.com/exploits/38453/