CVE-2008-1527
Last modified
CVE-2008-1527 is a vulnerability of currently unknown severity. ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.. EPSS estimates a 1.42% chance of exploitation in the next 30 days.
Description
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zyxel | Prestige 660 | h-d1 | — |
| Zyxel | Prestige 660 | h-d3 | — |
| Zyxel | Prestige 661 | hw-d1 | — |
| Zyxel | Zynos | 3.40 | Agd.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1527?
How severe is CVE-2008-1527?
How do I fix CVE-2008-1527?
Are you affected by CVE-2008-1527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
