CVE-2019-6725: Critical severity zyxel p660hn-t1a v1 firmware vulnerability
Published May 31, 2019
·Updated
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
Affected Software
2 affected components
Zyxel P-660hn-t1 Firmware=2.00\(aakk.3\)
Zyxel P-660HN-T1=2
Event History
May 31, 2019
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-6725?
The severity of CVE-2019-6725 is critical with a CVSS score of 9.8.
2
How can I protect my ZyXEL P-660HN-T1 V2 device from CVE-2019-6725?
To protect your ZyXEL P-660HN-T1 V2 device from CVE-2019-6725, ensure that the rpWLANRedirect.asp ASP page requires authentication before granting access.
3
Can the admin user's password be obtained without authentication due to CVE-2019-6725?
Yes, the admin user's password can be obtained without authentication by viewing the HTML source code after accessing the rpWLANRedirect.asp ASP page on affected devices.