PoC Index

CVE-2014-9118

HIGH 9.0EPSS 53.4%

The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
53.36% chance of exploitation in the next 30 days, 99th percentile
Published
2017-10-17
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related