CVE Vulnerabilities

CVE-2008-1524

Published: Mar 26, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has public as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.

Affected Software

NameVendorStart VersionEnd Version
Prestige_660Zyxelh-d1 (including)h-d1 (including)
Prestige_660Zyxelh-d3 (including)h-d3 (including)
Prestige_661Zyxelhw-d1 (including)hw-d1 (including)
ZynosZyxel3.40-agd.2 (including)3.40-agd.2 (including)
ZynosZyxel3.40-agl.3 (including)3.40-agl.3 (including)
ZynosZyxel3.40-ahq.0 (including)3.40-ahq.0 (including)
ZynosZyxel3.40-ahq.3 (including)3.40-ahq.3 (including)
ZynosZyxel3.40-ahz.0 (including)3.40-ahz.0 (including)
ZynosZyxel3.40-atm.0 (including)3.40-atm.0 (including)

References