CVE-2014-9118 is a critical command injection vulnerability affecting the web administrative portal of Zhone zNID GPON 2426A devices running firmware versions prior to S3.0.501. This flaw allows remote, authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the ipAddr parameter of the zhnping.cmd script. With a CVSS v3 score of 8.8 (High), this vulnerability presents a significant risk, enabling complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry exists, and community discussion and media coverage suggest awareness and potential for exploitation, including its reported use in the EnemyBot DDoS botnet.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dasanzhone:znid_2426a_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.