packetstormsecurity.com
http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html CVE-2014-9118
HIGH
dasanzhone znid_2426a_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2014-9118 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
znid_2426a_firmwareBrowse dasanzhone / znid_2426a_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBZHONE < S3.0.501 - Multiple VulnerabilitiesExploitDB exploitby Lyon YangNot analyzed1 file
References
520151013 Vantage Point Security Advisory 2015-002mailing list
http://seclists.org/fulldisclosure/2015/Oct/57 20151012 Multiple Vulnerabilities found in ZHONEmailing list
http://www.securityfocus.com/archive/1/536663/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-9118 38453exploit
https://www.exploit-db.com/exploits/38453