packetstormsecurity.com
http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html CVE-2014-8356
HIGH
dasanzhone znid_2426a_firmware Authorization Bypass Through User-Controlled Key
Record summary
CVE-2014-8356 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 13, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
znid_2426a_firmwareBrowse dasanzhone / znid_2426a_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBZHONE < S3.0.501 - Multiple VulnerabilitiesExploitDB exploitby Lyon YangNot analyzed1 file
References
4seclists.org
http://seclists.org/fulldisclosure/2015/Oct/57 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8356 exploit-db.com
https://www.exploit-db.com/exploits/38453