CVE-2014-8356: Dasanzhone Znid 2426a Firmware

High severity, CVSS 8.8. EPSS: 5.6% chance of exploitation in the next 30 days.

The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.

Affected products

  • Dasanzhone Znid 2426a Firmware: before s3.0.501 (fixed in s3.0.501)

Published 2019-11-21. Last modified 2026-06-17.