CVE-2014-2321: ZTE f460

High severity, CVSS 10.0. EPSS: 59.3% chance of exploitation in the next 30 days.

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

Affected products

  • ZTE f460: affected versions not specified
  • ZTE f660: affected versions not specified

Published 2014-03-11. Last modified 2026-06-17.