Show filters
303 Total Results
Displaying 271-280 of 303
Sort by:
Attacker Value
Unknown
CVE-2008-1521
Disclosure Date: March 26, 2008 (last updated October 04, 2023)
ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to gain privileges by accessing administrative URIs, as demonstrated by rpSysAdmin.html.
0
Attacker Value
Unknown
CVE-2008-1526
Disclosure Date: March 26, 2008 (last updated February 15, 2024)
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
0
Attacker Value
Unknown
CVE-2008-1525
Disclosure Date: March 26, 2008 (last updated October 04, 2023)
The default SNMP configuration on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has a Trusted Host value of 0.0.0.0, which allows remote attackers to send SNMP requests from any source IP address.
0
Attacker Value
Unknown
CVE-2008-1528
Disclosure Date: March 26, 2008 (last updated October 04, 2023)
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.
0
Attacker Value
Unknown
CVE-2008-1160
Disclosure Date: March 25, 2008 (last updated February 14, 2024)
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2008-1256
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
0
Attacker Value
Unknown
CVE-2008-1257
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
0
Attacker Value
Unknown
CVE-2008-1261
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware provides different responses to admin page requests depending on whether a user is logged in, which allows remote attackers to obtain current login status by requesting an arbitrary admin URI.
0
Attacker Value
Unknown
CVE-2008-1255
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
0
Attacker Value
Unknown
CVE-2008-1260
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.
0