CVE-2014-4154: Medium severity ZTE Zxv10 W300 Firmware vulnerability
ZTE ZXV10 W300 router with firmware W300V1.0.0aZRDLK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4154?
CVE-2014-4154 is considered a high severity vulnerability due to the exposure of sensitive information without adequate access control.
How do I fix CVE-2014-4154?
To fix CVE-2014-4154, update the ZTE ZXV10 W300 router firmware to a version that addresses this security issue.
What type of attacks can exploit CVE-2014-4154?
CVE-2014-4154 can be exploited by remote attackers using direct requests to obtain sensitive PPPoE/PPPoA passwords.
Which devices are affected by CVE-2014-4154?
Devices affected by CVE-2014-4154 include the ZTE ZXV10 W300 router running firmware version 1.0.0a_ZRD_LK.
Is user interaction required to exploit CVE-2014-4154?
No, user interaction is not required to exploit CVE-2014-4154 as it can be executed remotely.