« Volver al listado

CVE-2008-1528

Estado: ModificadaMedia (4)—

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1528",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-03-26T10:44:00.000",
  "references": [
    {
      "url": "http://www.gnucitizen.org/projects/router-hacking-challenge/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41511",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gnucitizen.org/projects/router-hacking-challenge/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41511",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys."
    },
    {
      "lang": "es",
      "value": "Los routers ZyXEL Prestige, incluyendo los modelos P-660 y P-661 con firmware 3.40(AGD.2) hasta la 3.40(AHQ.3), permite a usuarios remotos autenticados obtener datos validados realizando peticiones HTML directas y después leyendo el código fuente HTML, tal y como se ha demostrado mediante una petición para  (1) RemMagSNMP.html, que revela las comunidades SNMP; o (2) WLAN.html, que revela claves WEP."
    }
  ],
  "lastModified": "2026-06-16T22:51:54.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:prestige_660:h-d1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9B37DD5-40E7-43E3-8183-A755C488E383"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:prestige_660:h-d3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2850459-830C-49FD-89F8-0693E6D33543"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:prestige_661:hw-d1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C2C98B6-E370-4E2C-988D-CC3F3AA78126"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:agd.2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC9ED360-9257-477C-8F21-0CD4C1D38F42"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:agl.3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B170D9D8-4A01-4A97-947C-F978B07045C2"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahq.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D759579-E9E7-4344-BA88-CACECFB9C731"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahq.3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35DB7E44-E00E-41E3-A701-FB5DAC8E48E1"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahz.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2344FB7D-785D-4C52-BF27-1EEAAB2726B8"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.40:atm.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEA7FE7B-31E2-4164-882B-2E9712F95044"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}