CVE-2014-0329 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 8.5% (pctl 95)
Patch early
A public exploit exists.
Description
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 8.52% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-255 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-02-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zte | zxv10 w300 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ZTE ZXV10 W300 Router - Hard-Coded Credentials | 2014-02-09 |
References
- http://blog.alguien.at/2014/02/hackeando-el-router-zte-zxv10-w300-v21.html
- http://osvdb.org/102816
- http://packetstormsecurity.com/files/125142/ZTE-ZXV10-W300-Hardcoded-Credentials.html
- http://www.kb.cert.org/vuls/id/228886
- http://www.securityfocus.com/bid/65310
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90958
- http://blog.alguien.at/2014/02/hackeando-el-router-zte-zxv10-w300-v21.html
- http://osvdb.org/102816
- http://packetstormsecurity.com/files/125142/ZTE-ZXV10-W300-Hardcoded-Credentials.html
- http://www.kb.cert.org/vuls/id/228886
- http://www.securityfocus.com/bid/65310
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90958
→ the Explorer · watch your stack · NVD