CVE-2014-2321 describes a critical vulnerability in ZTE F460 and F660 cable modems, where the web_shell_cmd.gch script allows remote, unauthenticated attackers to gain administrative access. This is achieved by sending crafted "sendcmd" requests, such as those enabling a TELNET service with arbitrary credentials. The vulnerability carries a CVSS score of 10.0, indicating maximum severity with complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, its high EPSS score and multiple media mentions, including its use by the BotenaGo botnet, confirm active exploitation and significant community attention, with Nuclei templates available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:zte:f460:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:zte:f660:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.