7.5
CVSSv2

CVE-2008-1524

Published: 26/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) up to and including 3.40(AHQ.3), has "public" as its default community for both (1) read and (2) write operations, which allows remote malicious users to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel prestige 660 h-d1

zyxel prestige 660 h-d3

zyxel zynos 3.40

zyxel prestige 661 hw-d1