Record summary

CVE-2014-9118 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBZHONE < S3.0.501 - Multiple VulnerabilitiesExploitDB exploitby Lyon YangNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

5