CVE Vulnerabilities

CVE-2008-1524

Published: Mar 26, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has public as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.

Affected Software

Name Vendor Start Version End Version
Prestige_660 Zyxel h-d1 (including) h-d1 (including)
Prestige_660 Zyxel h-d3 (including) h-d3 (including)
Prestige_661 Zyxel hw-d1 (including) hw-d1 (including)
Zynos Zyxel 3.40-agd.2 (including) 3.40-agd.2 (including)
Zynos Zyxel 3.40-agl.3 (including) 3.40-agl.3 (including)
Zynos Zyxel 3.40-ahq.0 (including) 3.40-ahq.0 (including)
Zynos Zyxel 3.40-ahq.3 (including) 3.40-ahq.3 (including)
Zynos Zyxel 3.40-ahz.0 (including) 3.40-ahz.0 (including)
Zynos Zyxel 3.40-atm.0 (including) 3.40-atm.0 (including)

References