ZyXEL DSL Modem Default Remote Administration Password Vulnerability
BID:6671
Info
ZyXEL DSL Modem Default Remote Administration Password Vulnerability
| Bugtraq ID: | 6671 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2003 12:00AM |
| Updated: | Jan 23 2003 12:00AM |
| Credit: | Discovered by http-equiv <[email protected]>. |
| Vulnerable: |
ZyXEL Prestige 645 ZyXEL Prestige 642R-I ZyXEL Prestige 642R ZyXEL Prestige 642ME ZyXEL Prestige 642M-I ZyXEL Prestige 642M ZyXEL Prestige 642 |
| Not Vulnerable: | |
Discussion
ZyXEL DSL Modem Default Remote Administration Password Vulnerability
It has been reported that the administration interface on some ZyXEL devices, including the 642 and 645 series, is remotely accessible and pre-set with a default username and password.
It has additionally been reported that sensitive information set in the devices by ISPs, such as user email addresses, may be obtained by remote attackers.
It is important to note that other ZyXEL devices may share this default account.
It has been reported that the administration interface on some ZyXEL devices, including the 642 and 645 series, is remotely accessible and pre-set with a default username and password.
It has additionally been reported that sensitive information set in the devices by ISPs, such as user email addresses, may be obtained by remote attackers.
It is important to note that other ZyXEL devices may share this default account.