ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prestige_660 | Zyxel | h-d1 (including) | h-d1 (including) |
Prestige_660 | Zyxel | h-d3 (including) | h-d3 (including) |
Prestige_661 | Zyxel | hw-d1 (including) | hw-d1 (including) |
Zynos | Zyxel | 3.40-agd.2 (including) | 3.40-agd.2 (including) |
Zynos | Zyxel | 3.40-agl.3 (including) | 3.40-agl.3 (including) |
Zynos | Zyxel | 3.40-ahq.0 (including) | 3.40-ahq.0 (including) |
Zynos | Zyxel | 3.40-ahq.3 (including) | 3.40-ahq.3 (including) |
Zynos | Zyxel | 3.40-ahz.0 (including) | 3.40-ahz.0 (including) |
Zynos | Zyxel | 3.40-atm.0 (including) | 3.40-atm.0 (including) |