CVE-2004-1540: Medium severity Zyxel Prestige vulnerability
ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1540?
CVE-2004-1540 has a critical severity level due to the lack of authentication allowing unauthorized access to router configurations.
How do I fix CVE-2004-1540?
To fix CVE-2004-1540, disable HTTP remote administration on affected ZyXEL Prestige routers.
Which devices are affected by CVE-2004-1540?
CVE-2004-1540 affects various ZyXEL Prestige and Zynos routers with HTTP remote administration enabled.
Can CVE-2004-1540 be exploited remotely?
Yes, CVE-2004-1540 can be exploited remotely without authentication, allowing attackers to alter router settings.
What action should I take if I am using an affected router version for CVE-2004-1540?
If using an affected version, immediately apply security best practices by disabling remote administration and securing your network.