P-660HW series router
by Zyxel
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-1255 | 0.00 | — | 0.04 | Mar 10, 2008 | The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user. | |||
| CVE-2008-1256 | 0.00 | — | 0.03 | Mar 10, 2008 | The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access. | |||
| CVE-2008-1254 | 0.00 | — | 0.01 | Mar 10, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors. | |||
| CVE-2008-1257 | 0.00 | — | 0.02 | Mar 10, 2008 | Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter. |
- CVE-2008-1255Mar 10, 2008risk 0.00cvss —epss 0.04
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
- CVE-2008-1256Mar 10, 2008risk 0.00cvss —epss 0.03
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
- CVE-2008-1254Mar 10, 2008risk 0.00cvss —epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
- CVE-2008-1257Mar 10, 2008risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.