search menu icon-carat-right cmu-wordmark

CERT Coordination Center

ZTE F460/F660 cable modems contain an unauthenticated backdoor

Vulnerability Note VU#600724

Original Release Date: 2014-03-04 | Last Revised: 2014-03-19

Overview

ZTE F460/F660 cable modems contain an unauthenticated backdoor.

Description

ZTE F460/F660 cable modems contain an unauthenticated backdoor. The web_shell_cmd.gch script accepts unauthenticated commands that have administrative access to the device. It has been reported that the web_shell_cmd.gch script is sometimes accessible from the WAN interface making exploitation of this backdoor from the Internet possible in certain cases.

Additional details may be found in Rapid7's R7-2013-18 advisory.

ZTE has provided a statement about this vulnerability.

Impact

An unauthenticated attacker can run commands with administrator level access on the device.

Solution

We are currently unaware of a practical solution to this problem. Please consider the following workaround.

Remove Affected Script

Users can log into the device and manually delete the web_shell_cmd.gch script.

Vendor Information

600724
 

CVSS Metrics

Group Score Vector
Base 8.3 AV:A/AC:L/Au:N/C:C/I:C/A:C
Temporal 7.1 E:H/RL:W/RC:UC
Environmental 5.3 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Rapid7 for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

CVE IDs: None
Date Public: 2014-03-03
Date First Published: 2014-03-04
Date Last Updated: 2014-03-19 14:30 UTC
Document Revision: 17

Sponsored by CISA.