CVE-2014-8357: Dasanzhone Znid 2426a Firmware
High severity, CVSS 8.8. EPSS: 5.4% chance of exploitation in the next 30 days.
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
Affected products
- Dasanzhone Znid 2426a Firmware: before s3.0.501 (fixed in s3.0.501)
Published 2017-10-17. Last modified 2026-06-17.