First published: Tue Mar 11 2014(Updated: )
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE F460 | ||
ZTE F660 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2321 has been classified as a high severity vulnerability due to its potential to allow unauthorized administrative access to affected devices.
To mitigate CVE-2014-2321, users should disable the TELNET service and, if possible, update the firmware of the ZTE F460 or F660 modems to the latest version.
CVE-2014-2321 specifically affects the ZTE F460 and ZTE F660 cable modem models.
The potential impacts of CVE-2014-2321 include unauthorized access to network settings and configurations which can lead to data breaches and network disruption.
Monitoring device logs for unusual access patterns, especially related to TELNET commands, can help detect exploitation attempts related to CVE-2014-2321.