PT-2008-2852 · Zyxel · Zyxel P-2602Hw-D1A
Published
2008-03-10
·
Updated
2018-10-11
·
CVE-2008-1260
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zyxel P-2602HW-D1A router version 3.40(AJZ.1)
Description
The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities allow remote attackers to make changes to the router's configuration. Specifically, attackers can make the admin web server available on the Internet (WAN) interface by modifying the
WWWAccessInterface parameter in the Forms/RemMagWWW 1 endpoint. Additionally, attackers can change the IP whitelisting timeout by modifying the StdioTimout parameter in the Forms/rpSysAdmin 1 endpoint.Recommendations
For Zyxel P-2602HW-D1A router version 3.40(AJZ.1), consider restricting access to the
Forms/RemMagWWW 1 and Forms/rpSysAdmin 1 endpoints to minimize the risk of exploitation. Avoid using the WWWAccessInterface and StdioTimout parameters in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel P-2602Hw-D1A