← Vulnerability feed

Vulnerability record · CVE-2014-2321 · published 11 March 2014

CVE-2014-2321: ZTE F460/F660 cable modem web_shell_cmd.gch access control flaw

Zte · F460

The web_shell_cmd.gch endpoint on ZTE F460 and F660 cable modems fails to enforce access controls, letting remote attackers issue sendcmd requests that grant administrative access. Because the flaw is reachable over the network without authentication, any exposed modem can be fully taken over.

10.0 CVSS 2.0 High EPSS 59% · top 0.9% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote administrative takeover with public exploit detail and very high EPSS, though not in CISA KEV.

What it is

The web_shell_cmd.gch endpoint on ZTE F460 and F660 cable modems fails to enforce access controls, letting remote attackers issue sendcmd requests that grant administrative access. Because the flaw is reachable over the network without authentication, any exposed modem can be fully taken over.

Impact

An attacker gains full administrative control of the modem, including the ability to enable a TELNET service with attacker-chosen credentials, giving persistent remote access.

Attack surface

Reached over the network via HTTP requests to web_shell_cmd.gch; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.593, 99th percentile) and a public Rapid7 disclosure reference is tagged Exploit, indicating known public exploitation detail.

What to do

  • Apply vendor firmware updates for F460 and F660 modems; if no fix is available, replace or isolate affected devices.
  • Disable or block remote access to the modem web management interface from untrusted networks.
  • Restrict management access to a trusted LAN or management VLAN and block web_shell_cmd.gch at the network edge.
  • Change default administrative credentials and disable any TELNET service that is not explicitly required.
  • Monitor for unauthorized TELNET enablement or credential changes on modems.

Detection

  • Inspect HTTP logs or traffic for requests to web_shell_cmd.gch, especially sendcmd parameters such as set TelnetCfg.
  • Alert on unexpected TELNET service activation or new TELNET credentials on F460/F660 devices.
  • Monitor for anomalous administrative configuration changes originating from external IP addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-2321), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.