Release date:
Updated on:
Affected Systems:
ZTE F460
ZTE F660
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65962
ZTE F460/F660 is a cable modem product.
ZTE F460/F660 has an unauthenticated backdoor. The web_shell_cmd.gch script accepts unauthenticated commands. This script is sometimes accessible from the WAN interface. In some cases, attackers can use this backdoor to execute arbitrary administrator commands.
<* Source: unknown
Link: http://www.kb.cert.org/vuls/id/600724
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ZTE
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.zte.com.cn/
Refer:
Https://community.rapid7.com/community/infosec/blog/2014/03/03/disclosure-r7-2013-18-zte-f460-and-zte-f660-webshellcmdgch-backdoor
Http://www.myxzy.com/post-411.html