PT-2014-3562 · Zte · Zte Zxv10 W300
Publicado
2014-02-04
·
Atualizado
2017-08-29
·
CVE-2014-0329
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZTE ZXV10 W300 router version 2.1.0
Description
The issue concerns a hardcoded password for the admin account in the TELNET service, which can be determined by knowing the MAC address characters at the beginning of the password, allowing remote attackers to gain administrative access.
Recommendations
For ZTE ZXV10 W300 router version 2.1.0, consider changing the admin account password to a strong, unique password to prevent unauthorized access. As a temporary workaround, restrict access to the TELNET service until a more secure configuration can be implemented.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zte Zxv10 W300