CVE-2014-9118: Dasanzhone Znid 2426a Firmware
High severity, CVSS 8.8. EPSS: 53.4% chance of exploitation in the next 30 days.
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
Affected products
- Dasanzhone Znid 2426a Firmware: affected versions not specified
Published 2017-10-17. Last modified 2026-06-17.