Lucene search

K
cveMitreCVE-2008-1260
HistoryMar 10, 2008 - 5:44 p.m.

CVE-2008-1260

2008-03-1017:44:00
CWE-352
mitre
web.nvd.nist.gov
33
cve
zyxel
p-2602hw-d1a
router
csrf
vulnerabilities
remote attackers
admin web server
wan interface
ip whitelisting
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

54.2%

Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.

Affected configurations

Nvd
Node
zyxelp-2602hw-d1a3.40\(ajz.1\)
VendorProductVersionCPE
zyxelp-2602hw-d1a*cpe:2.3:h:zyxel:p-2602hw-d1a:*:*:3.40\(ajz.1\):*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

54.2%

Related for CVE-2008-1260