First published: Mon Mar 10 2008(Updated: )
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware provides different responses to admin page requests depending on whether a user is logged in, which allows remote attackers to obtain current login status by requesting an arbitrary admin URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel P-2602HW-D1A | =3.40\(ajz.1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1261 is classified as a medium-severity vulnerability.
To mitigate CVE-2008-1261, update the firmware of the Zyxel P-2602HW-D1A router to the latest version available.
CVE-2008-1261 is an authentication-related vulnerability that exposes login status through different responses to admin page requests.
The vulnerability affects users of the Zyxel P-2602HW-D1A router running firmware version 3.40(AJZ.1).
Yes, CVE-2008-1261 can be exploited remotely by attackers to glean information about the login status of the router.