Vulnerabilities > Zyxel > Prestige 661 > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-03-26 CVE-2008-1529 Credentials Management vulnerability in Zyxel Prestige 660, Prestige 661 and Zynos
ZyXEL Prestige routers have a minimum password length for the admin account that is too small, which makes it easier for remote attackers to guess passwords via brute force methods.
network
low complexity
zyxel CWE-255
5.0
2008-03-26 CVE-2008-1528 Improper Authentication vulnerability in Zyxel Prestige 660, Prestige 661 and Zynos
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.
network
low complexity
zyxel CWE-287
4.0
2008-03-26 CVE-2008-1525 Configuration vulnerability in Zyxel Prestige 660, Prestige 661 and Zynos
The default SNMP configuration on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has a Trusted Host value of 0.0.0.0, which allows remote attackers to send SNMP requests from any source IP address.
network
low complexity
zyxel CWE-16
5.0
2008-03-26 CVE-2008-1523 Information Exposure vulnerability in Zyxel Prestige 660, Prestige 661 and Zynos
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain ISP and Dynamic DNS credentials by sending a direct request for (1) WAN.html, (2) wzPPPOE.html, and (3) rpDyDNS.html, and then reading the HTML source.
network
low complexity
zyxel CWE-200
5.0
2008-03-26 CVE-2008-1521 Permissions, Privileges, and Access Controls vulnerability in Zyxel Prestige 660, Prestige 661 and Zynos
ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to gain privileges by accessing administrative URIs, as demonstrated by rpSysAdmin.html.
network
low complexity
zyxel CWE-264
6.5