VendorsZyxelp-660hwall versions
Vulnerabilities

Zyxel P-660HW T1 Model (initial release)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2008-1255
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
Published 2008-03-10 · Modified
10.0EPSS 0.039
CVE-2008-1256
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
Published 2008-03-10 · Modified
10.0EPSS 0.033
CVE-2017-17901
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
Published 2017-12-29 · Modified
7.8EPSS 0.023
CVE-2013-3588
The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.
Published 2014-04-02 · Modified
7.8EPSS 0.022
CVE-2014-4162
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.
Published 2014-06-16 · Modified
6.81 PoCEPSS 0.026
CVE-2008-1254
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
Published 2008-03-10 · Modified
6.8EPSS 0.010
CVE-2008-1257
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
Published 2008-03-10 · Modified
4.3EPSS 0.016