ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
| Software | From | Fixed in |
|---|---|---|
| zyxel / prestige | 645r_a1 | 645r_a1.x |
| zyxel / prestige | 650r | 650r.x |
| zyxel / zynos | 3.40 | 3.40.x |
| zyxel / prestige | 650h | 650h.x |
| zyxel / prestige | 650hw | 650hw.x |
| zyxel / prestige | 650hw_31 | 650hw_31.x |
| zyxel / zynos | is.3 | is.3.x |
| zyxel / zynos | is.5 | is.5.x |