CVE-2014-8356Active Exploitation(dasanzhone / znid_2426a)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dasanzhone znid_2426a systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • znid_2426a
  • znid_2426a_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
znid_2426aznid_2426a_firmware

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-25: 1Exploit Tool / Code · 2026-04-25: 1Active Exploitation · 2026-04-25: 104-25
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting Zhone GPON routers to deliver #Mirai (CVE-2014-8356) 2026-04-25 21:37:09 UTC Source IP: 163.61.39.140 🇮🇳 IOCs: hxxp://163.61.39.140/hiddenbin/boatnet.mips 163.61.39.140 🇮🇳 380c1a0da340b8c2aa6002616fcf7310 https://t.co/rLcPuoiiN5

    Post summary

    An RCE attempt exploiting CVE-2014-8356 on Zhone GPON routers was detected, with IOCs pointing to a binary that likely delivered Mirai malware.

    00010364
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdasanzhoneznid_2426a---
OSdasanzhoneznid_2426a_firmware---

Explore more