First published: Mon Mar 10 2008(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZyXEL P-660HW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1254 is classified as having a high severity due to potential unauthorized changes to critical router settings.
To fix CVE-2008-1254, it is recommended to update the firmware of the ZyXEL P-660HW router to the latest version provided by the manufacturer.
CVE-2008-1254 allows remote attackers to perform cross-site request forgery attacks that can alter DNS settings and manage the banned list.
Users of the ZyXEL P-660HW series router are affected by CVE-2008-1254.
To mitigate CVE-2008-1254, users should implement access controls and monitor router configurations regularly.