PT-2008-3085 · Zyxel · Zyxel Prestige

Published

2008-03-26

·

Updated

2024-02-14

·

CVE-2008-1526

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZyXEL Prestige routers versions 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3)
Description The issue is related to the calculation of an MD5 password hash without using a salt, making it easier for attackers to crack passwords.
Recommendations For versions 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), consider updating the firmware to a version that uses a salt when calculating password hashes as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2008-1526

Affected Products

Zyxel Prestige