VYPR
Unrated severityNVD Advisory· Published Mar 26, 2008· Updated Apr 23, 2026

CVE-2008-1527

CVE-2008-1527

Description

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.

Affected products

9
  • cpe:2.3:h:zyxel:prestige_660:h-d1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:h:zyxel:prestige_660:h-d1:*:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:prestige_660:h-d3:*:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:prestige_661:hw-d1:*:*:*:*:*:*:*
  • Zyxel/Zynos6 versions
    cpe:2.3:h:zyxel:zynos:3.40:agd.2:*:*:*:*:*:*+ 5 more
    • cpe:2.3:h:zyxel:zynos:3.40:agd.2:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:zynos:3.40:agl.3:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:zynos:3.40:ahq.0:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:zynos:3.40:ahq.3:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:zynos:3.40:ahz.0:*:*:*:*:*:*
    • cpe:2.3:h:zyxel:zynos:3.40:atm.0:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.