CVE-2008-1524 Information

Description

The SNMP service on ZyXEL Prestige routers including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3) has \public\ as its default community for both (1) read and (2) write operations which allows remote attackers to perform administrative actions via SNMP as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable which is displayed on the System Status page.

Reference

http://www.gnucitizen.org/projects/router-hacking-challenge/ http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf http://www.securityfocus.com/archive/1/489009/100/0/threaded

Share on: