CVE-2014-8357
HIGH EXPLOITEDZhone zNID GPON 2426A < S3.0.501 - Unauthenticated Password Disclosure via Session Key in URL
Title source: llmExploitation Summary
CVE-2014-8357 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Lyon Yang.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Zhone ZNID GPON routers, including insecure direct object reference, password disclosure, remote command injection, XSS, and privilege escalation. It provides proof-of-concept steps and affected URLs but does not include executable exploit code.
Description
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
Exploits (1)
This advisory details multiple vulnerabilities in Zhone ZNID GPON routers, including insecure direct object reference, password disclosure, remote command injection, XSS, and privilege escalation. It provides proof-of-concept steps and affected URLs but does not include executable exploit code.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H