MEDIUM · 6.4

CVE-2005-3725

Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or ...

Vulnerability Description

Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or spoofing the hardcoded DNS servers. NOTE: it could be argued that this issue reflects an inherent limitation of DNS itself, so perhaps it should not be included in CVE.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ZyxelPrestige 2000W V.1Voip Wi-Fi Phonewj.00.10

References

FAQ

What is CVE-2005-3725?

CVE-2005-3725 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or ...

How severe is CVE-2005-3725?

CVE-2005-3725 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3725?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Prestige 2000W V.1Voip Wi-Fi Phone.