🔙 목록으로 돌아가기

CVE-2014-2321: ZTE Cable Modem Web Shell

TitleZTE Cable Modem Web Shell
Authorgeeknik
SeverityCritical
ImpactRemote code execution
RemediationApply the latest firmware update provided by ZTE to fix the vulnerability
CVSS Score10
EPSS Score0.92497
CVE IDCVE-2014-2321
CWE IDCWE-264
Shodan Querycpe:"cpe:2.3:h:zte:f460"
Tags cve2014 cve iot zte vkev vuln

🔍 Vulnerability Description

ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests to web_shell_cmd.gch, as demonstrated by using “set TelnetCfg” commands to enable a TELNET service with specified credentials.

🌐 HTTP Request

GET /web_shell_cmd.gch HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-2321.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-2321.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A