packetstormsecurity.com
http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html CVE-2014-8357
HIGH
Zhone zNID GPON 2426A backupsettings.html Vulnerability
Record summary
CVE-2014-8357 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 13, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
znid_2426a_firmwareBrowse dasanzhone / znid_2426a_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBZHONE < S3.0.501 - Multiple VulnerabilitiesExploitDB exploitby Lyon YangNot analyzed1 file
References
520151013 Vantage Point Security Advisory 2015-002mailing list
http://seclists.org/fulldisclosure/2015/Oct/57 20151012 Multiple Vulnerabilities found in ZHONEmailing list
http://www.securityfocus.com/archive/1/536663/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8357 38453exploit
https://www.exploit-db.com/exploits/38453