Total vulnerabilities in the database
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.
Software | From | Fixed in |
---|---|---|
zyxel / zynos | 3.40-ahq.0 | 3.40-ahq.0.x |
zyxel / zynos | 3.40-agl.3 | 3.40-agl.3.x |
zyxel / zynos | 3.40-ahq.3 | 3.40-ahq.3.x |
zyxel / zynos | 3.40-ahz.0 | 3.40-ahz.0.x |
zyxel / prestige_661 | hw-d1 | hw-d1.x |
zyxel / prestige_660 | h-d3 | h-d3.x |
zyxel / zynos | 3.40-atm.0 | 3.40-atm.0.x |
zyxel / prestige_660 | h-d1 | h-d1.x |
zyxel / zynos | 3.40-agd.2 | 3.40-agd.2.x |