Dasanzhone Znid 2426A Firmware vulnerabilities
2 known vulnerabilities affecting dasanzhone/znid_2426a_firmware.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2014-8356P2HIGHCVSS 8.8ExploitedPoCfixed in s3.0.5012019-11-21
CVE-2014-8356 [HIGH] CWE-639 CVE-2014-8356: The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
nvd
CVE-2014-8357P2HIGHCVSS 8.8ExploitedPoCfixed in s3.0.5012017-10-17
CVE-2014-8357 [HIGH] CWE-255 CVE-2014-8357: backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
nvd