{"api_version":"1","generated_at":"2026-07-23T03:44:39+00:00","cve":"CVE-2004-0680","urls":{"html":"https://cve.report/CVE-2004-0680","api":"https://cve.report/api/cve/CVE-2004-0680.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0680","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0680"},"summary":{"title":"CVE-2004-0680","description":"Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-08-06 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/10669","name":"http://www.securityfocus.com/bid/10669","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Zoom Model 5560 X3 ETHERNET ADSL Modem Default Backdoor Account Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16639","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=108915255520924&w=2","name":"http://marc.info/?l=bugtraq&m=108915255520924&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'backdoor menu on conexant chipset dsl router (Zoom X3)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0680","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0680","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zoom","cpe5":"model_5560_x3_ethernet_adsl_modem","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:24:27.048Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040706 backdoor menu on conexant chipset dsl router (Zoom X3)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108915255520924&w=2"},{"name":"conexant-chipset-settings-restore(16639)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16639"},{"name":"10669","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10669"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-07-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040706 backdoor menu on conexant chipset dsl router (Zoom X3)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108915255520924&w=2"},{"name":"conexant-chipset-settings-restore(16639)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16639"},{"name":"10669","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10669"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0680","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040706 backdoor menu on conexant chipset dsl router (Zoom X3)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108915255520924&w=2"},{"name":"conexant-chipset-settings-restore(16639)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16639"},{"name":"10669","refsource":"BID","url":"http://www.securityfocus.com/bid/10669"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0680","datePublished":"2004-07-13T04:00:00.000Z","dateReserved":"2004-07-12T00:00:00.000Z","dateUpdated":"2024-08-08T00:24:27.048Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-08-06 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:zoom:model_5560_x3_ethernet_adsl_modem:*:*:*:*:*:*:*:*","matchCriteriaId":"2ACFA54E-21A0-42EE-8000-4DEA6D545C31"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"680","Ordinal":"1","Title":"CVE-2004-0680","CVE":"CVE-2004-0680","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"680","Ordinal":"1","NoteData":"Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.","Type":"Description","Title":"CVE-2004-0680"},{"CveYear":"2004","CveId":"680","Ordinal":"2","NoteData":"2004-07-13","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"680","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}