Vulnerabilities > CVE-2008-1526 - Use of Password Hash With Insufficient Computational Effort vulnerability in Zyxel products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zyxel
CWE-916

Summary

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.

Vulnerable Configurations

Part Description Count
OS
Zyxel
38
Hardware
Zyxel
19