CVE-2001-1135
ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- zyxel/prestige
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/203022
- http://www.securityfocus.com/archive/1/203592
- http://www.securityfocus.com/archive/1/204439Vendor Advisory
- http://www.securityfocus.com/archive/1/214971Vendor Advisory
- http://www.securityfocus.com/bid/3346Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7146
- http://www.securityfocus.com/archive/1/203022
- http://www.securityfocus.com/archive/1/203592
- http://www.securityfocus.com/archive/1/204439Vendor Advisory
- http://www.securityfocus.com/archive/1/214971Vendor Advisory
- http://www.securityfocus.com/bid/3346Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7146
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.