header-logo
Suggest Exploit
vendor:
ZXHN H108N R1A, ZXV10 W300
by:
Karn Ganeshen
6,1
CVSS
MEDIUM
Information Exposure, Improper Authorization, Cross-Site Request Forgery (CSRF), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
200, 285, 352, 78, 79
CWE
Product Name: ZXHN H108N R1A, ZXV10 W300
Affected Version From: ZTE.bhs.ZXHNH108NR1A.h_PE, W300V1.0.0f_ER1_PE
Affected Version To: ZTE.bhs.ZXHNH108NR1A.h_PE, W300V1.0.0f_ER1_PE
Patch Exists: YES
Related CWE: CVE-2015-7248, CVE-2015-7249, CVE-2015-7250, CVE-2015-7251, CVE-2015-7252
CPE: h:zte:zxhn_h108n_r1a, cpe:/h:zte:zxv10_w300
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015

ZTE ZXHN H108N R1A + ZXV10 W300 routers – multiple vulnerabilities

Multiple information exposure vulnerabilities enable an attacker to obtain credentials and other sensitive details about the ZXHN H108N R1A. User names and password hashes can be viewed in the page source of http://<IP>/cgi-bin/webproc. The configuration file of the device contains usernames, passwords, keys, and other values in plain text, which can be used by a user with lower privileges to gain admin account access. The ZXHN H108N R1A router, version ZTE.bhs.ZXHNH108NR1A.h_PE, does not properly restrict access to the web interface. An attacker can bypass authentication and gain access to the web interface without valid credentials. The ZXHN H108N R1A router, version ZTE.bhs.ZXHNH108NR1A.h_PE, is vulnerable to CSRF attacks. An attacker can send a malicious request to the router and perform actions with the privileges of the currently logged-in user. The ZXHN H108N R1A router, version ZTE.bhs.ZXHNH108NR1A.h_PE, is vulnerable to OS command injection. An attacker can inject arbitrary commands into the router and execute them with root privileges. The ZXHN H108N R1A router, version ZTE.bhs.ZXHNH108NR1A.h_PE, is vulnerable to XSS attacks. An attacker can inject malicious JavaScript into the router and execute it with the privileges of the currently logged-in user.

Mitigation:

Ensure that the router is running the latest version of the firmware and that all security patches are applied.
Source

Exploit-DB raw data: