CVE-2019-6725
Last modified
CVE-2019-6725 is a vulnerability of currently unknown severity. The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | P-660hn-T1 Firmware | 2.00\(aakk.3\) |
References
- https://seclists.org/bugtraq/2019/May/78Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/78Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6725?
How severe is CVE-2019-6725?
How do I fix CVE-2019-6725?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6713app\admin\controller\RouteController.php in ThinkCMF 5.0.190…
- CVE-2019-6714An issue was discovered in BlogEngine.NET through 3.3.6.0. A…
- CVE-2019-6715pub/sns.php in the W3 Total Cache plugin before 0.9.4 for Wo…7.5
- CVE-2019-6716An unauthenticated Insecure Direct Object Reference (IDOR) i…
- CVE-2019-6719An issue has been found in libIEC61850 v1.3.1. There is a us…
- CVE-2019-6724The barracudavpn component of the Barracuda VPN Client prior…
- CVE-2019-6726The WP Fastest Cache plugin through 0.8.9.0 for WordPress al…
- CVE-2019-6727This vulnerability allows remote attackers to execute arbitr…8.8
- CVE-2019-6728This vulnerability allows remote attackers to disclose sensi…6.5
- CVE-2019-6729This vulnerability allows remote attackers to execute arbitr…8.8
- CVE-2019-6730This vulnerability allows remote attackers to execute arbitr…8.8
- CVE-2019-6731This vulnerability allows remote attackers to execute arbitr…8.8
Are you affected by CVE-2019-6725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
