Vulnerabilities (CVE)

Filtered by vendor Dasanzhone Subscribe
Filtered by product Znid 2426a
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-8356 1 Dasanzhone 2 Znid 2426a, Znid 2426a Firmware 2023-12-10 6.5 MEDIUM 8.8 HIGH
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
CVE-2014-8357 1 Dasanzhone 2 Znid 2426a, Znid 2426a Firmware 2023-12-10 4.0 MEDIUM 8.8 HIGH
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
CVE-2014-9118 1 Dasanzhone 2 Znid 2426a, Znid 2426a Firmware 2023-12-10 9.0 HIGH 8.8 HIGH
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.