Dasanzhone
dasanzhone
4 CVEs • 4 products
Products (4)
Click to collapseToggle
Products (4)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dasanzhone 1Znid 2426a Firmware Nov 21, 2024 Nov 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference. |
1Dasanzhone 1Znid Gpon 2426a Eu Firmware Jun 17, 2026 Sep 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET pa...Show more |
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd. |
1Dasanzhone 1Znid 2426a Firmware May 13, 2026 Oct 17, 2017 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter i...Show more |