PT-2014-3562 · Zte · Zte Zxv10 W300

Publicado

2014-02-04

·

Atualizado

2017-08-29

·

CVE-2014-0329

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZTE ZXV10 W300 router version 2.1.0
Description The issue concerns a hardcoded password for the admin account in the TELNET service, which can be determined by knowing the MAC address characters at the beginning of the password, allowing remote attackers to gain administrative access.
Recommendations For ZTE ZXV10 W300 router version 2.1.0, consider changing the admin account password to a strong, unique password to prevent unauthorized access. As a temporary workaround, restrict access to the TELNET service until a more secure configuration can be implemented.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0329

Produtos afetados

Zte Zxv10 W300