ZyXEL Prestige 650 HW远程管理漏洞

ZyXEL Prestige 650 HW远程管理漏洞

漏洞ID 1108290 漏洞类型 访问验证错误
发布时间 2004-11-22 更新时间 2005-10-20
图片[1]-ZyXEL Prestige 650 HW远程管理漏洞-安全小百科CVE编号 CVE-2004-1540
图片[2]-ZyXEL Prestige 650 HW远程管理漏洞-安全小百科CNNVD-ID CNNVD-200412-1130
漏洞平台 Hardware CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24760
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-1130
|漏洞详情
ZyXELPrestige650HW是一款小型路由器。ZyXELPrestige650HW对HTTP远程管理限制不正确,远程攻击者可以利用这个漏洞直接重设路由器。由于对”/rpFWUpload.html”管理页缺少正确的访问限制,直接提交此页面可重设路由器配置。
|漏洞EXP
source: http://www.securityfocus.com/bid/11723/info

ZyXEL Prestige router series is reported prone to an access validation vulnerability. The vulnerability exists because the firmware of the router fails to restrict access to a configuration page that is a part of the ZyXEL Prestige HTTP based remote administration service.

A remote attacker may exploit this vulnerability to reset the configuration of the router.

http://www.example.com/rpFWUpload.html
|参考资料

来源:XF
名称:zyxel-configuration-reset(18202)
链接:http://xforce.iss.net/xforce/xfdb/18202
来源:BID
名称:11723
链接:http://www.securityfocus.com/bid/11723
来源:SECTRACK
名称:1012298
链接:http://securitytracker.com/id?1012298
来源:SECUNIA
名称:13278
链接:http://secunia.com/advisories/13278
来源:OSVDB
名称:12108
链接:http://www.osvdb.org/12108
来源:BUGTRAQ
名称:20041124Re:RouterZyXELPrestige650HWhttpremoteadmin.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110135136811344&w;=2
来源:BUGTRAQ
名称:20041121RouterZyXELPrestige650HWhttpremoteadmin.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110116413414615&w;=2
来源:NSFOCUS
名称:7147
链接:http://www.nsfocus.net/vulndb/7147

相关推荐: BEA WebLogic Server and WebLogic Express User Impersonation Vulnerability

BEA WebLogic Server and WebLogic Express User Impersonation Vulnerability 漏洞ID 1099730 漏洞类型 Unknown 发布时间 2003-07-31 更新时间 2003-07-3…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享