MEDIUM · 5.0

CVE-2004-1540

ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers ...

Vulnerability Description

ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
ZyxelPrestige645r_a1
ZyxelZynos3.40

References

FAQ

What is CVE-2004-1540?

CVE-2004-1540 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers ...

How severe is CVE-2004-1540?

CVE-2004-1540 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1540?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Prestige, Zyxel Zynos.