PT-2008-2852 · Zyxel · Zyxel P-2602Hw-D1A

Published

2008-03-10

·

Updated

2018-10-11

·

CVE-2008-1260

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zyxel P-2602HW-D1A router version 3.40(AJZ.1)
Description The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities allow remote attackers to make changes to the router's configuration. Specifically, attackers can make the admin web server available on the Internet (WAN) interface by modifying the WWWAccessInterface parameter in the Forms/RemMagWWW 1 endpoint. Additionally, attackers can change the IP whitelisting timeout by modifying the StdioTimout parameter in the Forms/rpSysAdmin 1 endpoint.
Recommendations For Zyxel P-2602HW-D1A router version 3.40(AJZ.1), consider restricting access to the Forms/RemMagWWW 1 and Forms/rpSysAdmin 1 endpoints to minimize the risk of exploitation. Avoid using the WWWAccessInterface and StdioTimout parameters in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1260

Affected Products

Zyxel P-2602Hw-D1A