Vulnerability record · CVE-2014-2321 · published 11 March 2014
CVE-2014-2321: ZTE F460/F660 cable modem web_shell_cmd.gch access control flaw
Zte · F460
The web_shell_cmd.gch endpoint on ZTE F460 and F660 cable modems fails to enforce access controls, letting remote attackers issue sendcmd requests that grant administrative access. Because the flaw is reachable over the network without authentication, any exposed modem can be fully taken over.
Description
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote administrative takeover with public exploit detail and very high EPSS, though not in CISA KEV.
What it is
The web_shell_cmd.gch endpoint on ZTE F460 and F660 cable modems fails to enforce access controls, letting remote attackers issue sendcmd requests that grant administrative access. Because the flaw is reachable over the network without authentication, any exposed modem can be fully taken over.
Impact
An attacker gains full administrative control of the modem, including the ability to enable a TELNET service with attacker-chosen credentials, giving persistent remote access.
Attack surface
Reached over the network via HTTP requests to web_shell_cmd.gch; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.593, 99th percentile) and a public Rapid7 disclosure reference is tagged Exploit, indicating known public exploitation detail.
What to do
- Apply vendor firmware updates for F460 and F660 modems; if no fix is available, replace or isolate affected devices.
- Disable or block remote access to the modem web management interface from untrusted networks.
- Restrict management access to a trusted LAN or management VLAN and block web_shell_cmd.gch at the network edge.
- Change default administrative credentials and disable any TELNET service that is not explicitly required.
- Monitor for unauthorized TELNET enablement or credential changes on modems.
Detection
- Inspect HTTP logs or traffic for requests to web_shell_cmd.gch, especially sendcmd parameters such as set TelnetCfg.
- Alert on unexpected TELNET service activation or new TELNET credentials on F460/F660 devices.
- Monitor for anomalous administrative configuration changes originating from external IP addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2321 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2321), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.