PT-2008-2852 · Zyxel · Zyxel P-2602Hw-D1A

Publicado

2008-03-10

·

Atualizado

2018-10-11

·

CVE-2008-1260

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zyxel P-2602HW-D1A router version 3.40(AJZ.1)
Description The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities allow remote attackers to make changes to the router's configuration. Specifically, attackers can make the admin web server available on the Internet (WAN) interface by modifying the WWWAccessInterface parameter in the Forms/RemMagWWW 1 endpoint. Additionally, attackers can change the IP whitelisting timeout by modifying the StdioTimout parameter in the Forms/rpSysAdmin 1 endpoint.
Recommendations For Zyxel P-2602HW-D1A router version 3.40(AJZ.1), consider restricting access to the Forms/RemMagWWW 1 and Forms/rpSysAdmin 1 endpoints to minimize the risk of exploitation. Avoid using the WWWAccessInterface and StdioTimout parameters in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1260

Produtos afetados

Zyxel P-2602Hw-D1A