PT-2017-7168 · Zyxel · P-660Hn-51+22
Stefan ViehbཬK
·
Published
2017-09-27
·
Updated
2017-10-11
·
CVE-2015-7256
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points
ZyXEL P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs
ZyXEL PMG5318-B20A GPONs
ZyXEL SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways
ZyXEL GS1900-8 and GS1900-24 switches
ZyXEL C1000Z, Q1000, FR1000Z, and P8702N project models
Description
The issue is related to the use of non-unique X.509 certificates and SSH host keys in various ZyXEL devices.
Recommendations
For all affected devices, consider regenerating unique X.509 certificates and SSH host keys to prevent potential man-in-the-middle attacks or unauthorized access.
As a temporary workaround, restrict access to sensitive areas of the network to minimize the risk of exploitation.
Avoid using the affected devices for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
C1000Z
Fr1000Z
Gs1900-24
Gs1900-8
Nwa1100-N
Nwa1121-Ni
Nwa1123-Ac
Nwa1123-Ni
P-660Hn-51
P-663Hn-51
P8702N
Pmg5318-B20A
Q1000
Sbg3300-N000
Sbg3300-Nb00
Sbg3500-N000
Vmg1312-B10A
Vmg1312-B30A
Vmg4380-B10A
Vmg8324-B10A
Vmg8924-B10A
Vmg8924-B30A
Vsg1435-B101