PT-2014-3562 · Zte · Zte Zxv10 W300

Published

2014-02-04

·

Updated

2017-08-29

·

CVE-2014-0329

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZTE ZXV10 W300 router version 2.1.0
Description The issue concerns a hardcoded password for the admin account in the TELNET service, which can be determined by knowing the MAC address characters at the beginning of the password, allowing remote attackers to gain administrative access.
Recommendations For ZTE ZXV10 W300 router version 2.1.0, consider changing the admin account password to a strong, unique password to prevent unauthorized access. As a temporary workaround, restrict access to the TELNET service until a more secure configuration can be implemented.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0329

Affected Products

Zte Zxv10 W300