S4E just found a medium [ai] private ip disclosure detection scanner
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2014-2321 Scanner

CVE-2014-2321 scanner - Improper Access Control vulnerability in ZTE F460 and F660 cable modems

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2014-2321
10.0
CVSS

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ZTE F460 and F660 cable modems are widely used in homes and offices for internet connectivity. These modems come with a host of features such as dual-band WiFi, robust security, and user-friendly interfaces. They provide users with reliable internet connectivity and allow them to connect multiple devices to the internet simultaneously. The ZTE F460 and F660 cable modems are popular for their affordability and easy-to-use interfaces, making them an ideal choice for consumers.

The CVE-2014-2321 vulnerability is a serious security flaw that was detected in the web_shell_cmd.gch on ZTE F460 and F660 cable modems. This vulnerability can be exploited by remote attackers to obtain administrative access via sendcmd requests. By using "set TelnetCfg" commands, an attacker can enable a TELNET service with specified credentials, allowing them to assume full control of the system. This security flaw was first discovered in 2014 but is still prevalent in some modems in use today.

Exploiting this vulnerability can lead to serious consequences, such as unauthorized access and control of the modem. Attackers can gain administrative access to the modem, giving them complete control over the network. They can manipulate network settings, view user data, and potentially steal sensitive information. This can have serious implications for individuals and businesses alike, leading to data breaches, security breaches, and other negative outcomes.

At s4e.io, we provide a wide range of tools and resources that help users protect their digital assets from security vulnerabilities. Our platform is easy-to-use and provides users with timely and actionable information on the latest security threats and vulnerabilities. By staying informed and taking the necessary precautions, users can protect their networks from potential threats and safeguard their data. We encourage our readers to utilize these resources to ensure their networks are always secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update the firmware to the latest version, which should have addressed the security issue
  • Disable TELNET services on the modem
  • Change the login credentials of the modem to prevent unauthorized access
  • Use a strong password that is difficult to guess
  • Regularly monitor the network for any suspicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-2321 scanner - Improper Access Control vulnerability in ZTE F460 and F660 cable modems S4E