CVE-2008-1523: Infoleak
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain ISP and Dynamic DNS credentials by sending a direct request for (1) WAN.html, (2) wzPPPOE.html, and (3) rpDyDNS.html, and then reading the HTML source.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1523?
CVE-2008-1523 is classified as a medium-severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2008-1523?
To fix CVE-2008-1523, users should update their ZyXEL Prestige routers to the latest firmware version that addresses this vulnerability.
What devices are affected by CVE-2008-1523?
CVE-2008-1523 affects ZyXEL Prestige routers, including models P-660, P-661, and P-662 with specific versions of firmware.
Can remote authenticated users exploit CVE-2008-1523?
Yes, remote authenticated users can exploit CVE-2008-1523 to obtain ISP and Dynamic DNS credentials by accessing certain URLs.
What should I check if I have an affected ZyXEL router for CVE-2008-1523?
If you have an affected ZyXEL router, check your firmware version and promptly apply any available security updates.