First published: Thu Nov 20 2014(Updated: )
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Zxhn H108l Firmware | =4.0.0d_zrq_gr4 | |
ZTE ZXHN H108L |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8493 is classified as a medium severity vulnerability.
To mitigate CVE-2014-8493, update the ZTE ZXHN H108L firmware to a version that addresses this vulnerability.
CVE-2014-8493 allows remote attackers to modify the CWMP configuration of the vulnerable device.
CVE-2014-8493 specifically affects the ZTE ZXHN H108L running firmware version 4.0.0d_ZRQ_GR4.
Yes, CVE-2014-8493 can be exploited by remote attackers without authentication.