VulnerabilityModified
CVE-2008-1160
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
CRITICAL 9.8EPSS 14.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 14.76% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- zyxel/zywall 1050 firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0803-exploits/ZyWALL.pdfBroken Link
- http://secunia.com/advisories/29237Broken Link, Vendor Advisory
- http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-%28default-pass%29-remote-root-vulnerability-2008032143791/Broken Link, URL Repurposed
- http://www.securityfocus.com/bid/28184Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0990/referencesBroken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41424Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5289Third Party Advisory, VDB Entry
- http://packetstormsecurity.org/0803-exploits/ZyWALL.pdfBroken Link
- http://secunia.com/advisories/29237Broken Link, Vendor Advisory
- http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-%28default-pass%29-remote-root-vulnerability-2008032143791/Broken Link, URL Repurposed
- http://www.securityfocus.com/bid/28184Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0990/referencesBroken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41424Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5289Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.