HIGH · 9.3

CVE-2014-0329

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging kn...

Vulnerability Description

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ZteZxv10 W3002.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0329?

CVE-2014-0329 is a vulnerability with a CVSS score of 9.3 (HIGH). The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging kn...

How severe is CVE-2014-0329?

CVE-2014-0329 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0329?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxv10 W300.