CVE-2004-0680
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.61% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- zoom/model 5560 x3 ethernet adsl modem
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108915255520924&w=2
- http://www.securityfocus.com/bid/10669Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16639
- http://marc.info/?l=bugtraq&m=108915255520924&w=2
- http://www.securityfocus.com/bid/10669Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16639
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.