Vulnerabilities > Zyxel > P 660Hw

DATE CVE VULNERABILITY TITLE RISK
2017-12-29 CVE-2017-17901 Resource Exhaustion vulnerability in Zyxel P-660Hw Firmware
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
network
low complexity
zyxel CWE-400
7.8
2014-06-16 CVE-2014-4162 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel P-660Hw T1
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.
network
zyxel CWE-352
6.8
2014-04-02 CVE-2013-3588 Improper Input Validation vulnerability in Zyxel products
The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.
network
low complexity
zyxel CWE-20
7.8
2008-03-10 CVE-2008-1257 Cross-Site Scripting vulnerability in Zyxel products
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
network
zyxel CWE-79
4.3
2008-03-10 CVE-2008-1256 Remote Security vulnerability in P-660Hw
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
network
low complexity
zyxel
critical
10.0
2008-03-10 CVE-2008-1255 Permissions, Privileges, and Access Controls vulnerability in Zyxel P-660Hw
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
network
low complexity
zyxel CWE-264
critical
10.0
2008-03-10 CVE-2008-1254 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel P-660Hw
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
network
zyxel CWE-352
6.8