CVE-2015-7251
Description
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
In plain language
AI Worth attentionZTE ZXHN H108N R1A firmware before ZTE.bhs.ZXHNH108NR1A.k_PE can let a network attacker take over the router, so affected businesses should act.
Unauthenticated network administrative access is possible because the device exposes a hardcoded root credential through TELNET.
What to do now
- Check whether you use a ZTE ZXHN H108N R1A router and identify its installed firmware version.
- If it is before ZTE.bhs.ZXHNH108NR1A.k_PE, contact ZTE or your internet provider for a supported replacement or firmware update; no confirmed fixed version is available in the patch findings.
- Disable TELNET access, especially from the internet, until the device is replaced or updated.
- Change router administrator passwords and review its configuration for unfamiliar settings after securing access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-7251 and every CVE in our database. Create a free account — no credit card required.
Create Free Account