Vulnerabilities > Zyxel > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-03-25 CVE-2008-1160 Use of Hard-coded Credentials vulnerability in Zyxel Zywall 1050 Firmware
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
network
low complexity
zyxel CWE-798
critical
9.8
2008-03-10 CVE-2008-1259 Improper Authentication vulnerability in Zyxel P-2602Hw-D1A
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
network
zyxel CWE-287
critical
9.3
2008-03-10 CVE-2008-1256 Remote Security vulnerability in P-660Hw
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
network
low complexity
zyxel
critical
10.0
2008-03-10 CVE-2008-1255 Permissions, Privileges, and Access Controls vulnerability in Zyxel P-660Hw
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
network
low complexity
zyxel CWE-264
critical
10.0