ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
2004-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Hardware | zyxel | prestige | 645r_a1 | Yes |
| Hardware | zyxel | prestige | 650h | Yes |
| Hardware | zyxel | prestige | 650hw | Yes |
| Hardware | zyxel | prestige | 650hw_31 | Yes |
| Hardware | zyxel | prestige | 650r | Yes |
| Hardware | zyxel | zynos | 3.40 | Yes |
| Hardware | zyxel | zynos | is.3 | Yes |
| Hardware | zyxel | zynos | is.5 | Yes |