PT-2019-8306 · Zyxel · Zyxel P660Hn-T1A

Pedro Ribeiro

·

Published

2019-05-02

·

Updated

2019-05-03

·

CVE-2017-18371

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6
Description The issue concerns default passwords for user accounts in the router, including two hardcoded service accounts. One account has the username true and password true, and another has the username supervisor and password zyad1234. These accounts can be used to login to the web interface, potentially allowing for authenticated command injections and changes to router settings for malicious purposes.
Recommendations For ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6, change the default passwords of the true and supervisor accounts to secure passwords to prevent unauthorized access. Consider disabling these accounts if they are not necessary for the router's operation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18371

Affected Products

Zyxel P660Hn-T1A