Loading vulnerability details…
CVSS v3.1
N/A
EPSS
53.36%
Published
Oct 17, 2017
Modified
May 12, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
Weaknesses (CWE)
Affected Products (2)
References (8)