CVE Vulnerabilities

CVE-2008-1528

Improper Authentication

Published: Mar 26, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Prestige_660Zyxelh-d1 (including)h-d1 (including)
Prestige_660Zyxelh-d3 (including)h-d3 (including)
Prestige_661Zyxelhw-d1 (including)hw-d1 (including)
ZynosZyxel3.40-agd.2 (including)3.40-agd.2 (including)
ZynosZyxel3.40-agl.3 (including)3.40-agl.3 (including)
ZynosZyxel3.40-ahq.0 (including)3.40-ahq.0 (including)
ZynosZyxel3.40-ahq.3 (including)3.40-ahq.3 (including)
ZynosZyxel3.40-ahz.0 (including)3.40-ahz.0 (including)
ZynosZyxel3.40-atm.0 (including)3.40-atm.0 (including)

Potential Mitigations

References