peter bassill · operator
$ cve CVE-2014-0329 JSON

CVE-2014-0329 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS8.52% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploityes
Published2014-02-04
Last modified2026-06-17

Affected (1)

VendorProduct
ztezxv10 w300

Public exploits

SourceTitleDate
exploit-dbZTE ZXV10 W300 Router - Hard-Coded Credentials2014-02-09

References

→ the Explorer  ·  watch your stack  ·  NVD