PT-2019-8306 · Zyxel · Zyxel P660Hn-T1A
Pedro Ribeiro
·
Published
2019-05-02
·
Updated
2019-05-03
·
CVE-2017-18371
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6
Description
The issue concerns default passwords for user accounts in the router, including two hardcoded service accounts. One account has the username
true and password true, and another has the username supervisor and password zyad1234. These accounts can be used to login to the web interface, potentially allowing for authenticated command injections and changes to router settings for malicious purposes.Recommendations
For ZyXEL P660HN-T1A v2 TCLinux Fw version 7.3.37.6, change the default passwords of the
true and supervisor accounts to secure passwords to prevent unauthorized access. Consider disabling these accounts if they are not necessary for the router's operation.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel P660Hn-T1A