5
CVSSv2

CVE-2004-1540

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote malicious users to reset the router configuration file.

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel prestige 645r_a1

zyxel prestige 650h

zyxel prestige 650hw

zyxel prestige 650hw_31

zyxel prestige 650r

zyxel zynos 3.40

zyxel zynos is.3

zyxel zynos is.5

Exploits

source: wwwsecurityfocuscom/bid/11723/info ZyXEL Prestige router series is reported prone to an access validation vulnerability The vulnerability exists because the firmware of the router fails to restrict access to a configuration page that is a part of the ZyXEL Prestige HTTP based remote administration service A remote attacker may ...