Lyrie
Lyrie Research
CVSS 103 sources verified·1 min read
By Lyrie Threat Intelligence·5/6/2026

CRITICAL: CVE-2014-2321 (CVSS 10) — zte f460

CVE: CVE-2014-2321

CVSS: 10 (2.0) — AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: CRITICAL

Status: Critical advisory

Affected

  • zte f460
  • zte f660

Summary

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

Verified Sources

References

  • http://www.kb.cert.org/vuls/id/600724
  • http://www.myxzy.com/post-411.html
  • https://community.rapid7.com/community/infosec/blog/2014/03/03/disclosure-r7-2013-18-zte-f460-and-zte-f660-webshellcmdgch-backdoor
  • http://www.kb.cert.org/vuls/id/600724
  • http://www.myxzy.com/post-411.html
  • https://community.rapid7.com/community/infosec/blog/2014/03/03/disclosure-r7-2013-18-zte-f460-and-zte-f660-webshellcmdgch-backdoor

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE