PT-2014-3562 · Zte · Zte Zxv10 W300
Published
2014-02-04
·
Updated
2017-08-29
·
CVE-2014-0329
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZTE ZXV10 W300 router version 2.1.0
Description
The issue concerns a hardcoded password for the admin account in the TELNET service, which can be determined by knowing the MAC address characters at the beginning of the password, allowing remote attackers to gain administrative access.
Recommendations
For ZTE ZXV10 W300 router version 2.1.0, consider changing the admin account password to a strong, unique password to prevent unauthorized access. As a temporary workaround, restrict access to the TELNET service until a more secure configuration can be implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zte Zxv10 W300