CVE-2019-6725
Last modified
CVE-2019-6725 is a vulnerability of currently unknown severity. The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | P-660hn-T1 Firmware | 2.00\(aakk.3\) |
References
- https://seclists.org/bugtraq/2019/May/78Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/78Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6725?
How severe is CVE-2019-6725?
How do I fix CVE-2019-6725?
Are you affected by CVE-2019-6725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
