PT-2019-8306 · Zyxel · Zyxel P660Hn-T1A

Pedro Ribeiro

·

Publicado

2019-05-02

·

Atualizado

2019-05-03

·

CVE-2017-18371

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6
Description The issue concerns default passwords for user accounts in the router, including two hardcoded service accounts. One account has the username true and password true, and another has the username supervisor and password zyad1234. These accounts can be used to login to the web interface, potentially allowing for authenticated command injections and changes to router settings for malicious purposes.
Recommendations For ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6, change the default passwords of the true and supervisor accounts to secure passwords to prevent unauthorized access. Consider disabling these accounts if they are not necessary for the router's operation.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-18371

Produtos afetados

Zyxel P660Hn-T1A