CVE-2008-1526
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-916
- Affected
- zyxel/p-663hn-51 firmware · zyxel/p-660h-61 firmware · zyxel/p-660h-63 firmware · zyxel/p-660h-67 firmware · zyxel/p-660h-d1 firmware · zyxel/p-660h-d3 firmware · zyxel/p-660hn-51 firmware · zyxel/p-660h-t1 firmware · zyxel/p-660hw d1 firmware · zyxel/p-660hw d3 firmware · zyxel/p-660hw t3 firmware · zyxel/p-661hnu-f1 firmware · zyxel/p-661h firmware · zyxel/p-661hw-d1 firmware · zyxel/p-661hnu-f3 firmware · zyxel/p-662hw-d3 firmware · zyxel/p-662hw-d firmware · zyxel/p-662hw-d1 firmware · zyxel/p-662h-61 firmware
- Source
- cve@mitre.org
References
- http://www.gnucitizen.org/projects/router-hacking-challenge/Broken Link
- http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdfBroken Link
- http://www.securityfocus.com/archive/1/489009/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.gnucitizen.org/projects/router-hacking-challenge/Broken Link
- http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdfBroken Link
- http://www.securityfocus.com/archive/1/489009/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.