vendor:
ZyWALL
by:
Pranav Joshi
7.5
CVSS
HIGH
Remote Root Vulnerability
287
CWE
Product Name: ZyWALL
Affected Version From: ZyWall 1050
Affected Version To: Other versions could be affected as well.
Patch Exists: YES
Related CWE: CVE-2008-1160
CPE: h:zyxel:zywall_1050
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
ZyXEL ZyWALL Quagga/Zebra Remote Root Vulnerability
The vulnerability in the Quagga/Zebra routing daemon, exists due to the fact that the appliance fails to change the password needed to login into the Quagga/Zebra daemon running on ports 2601, 2602 (Quagga/RIP) & 2604 (Quagga/OSPF) /TCP, even though the password of the appliance has been changed an attacker can still use the default password ‘zebra’ to log into the Quagga/Zebra service to view and manipulate the routing information etc. of the appliance.
Mitigation:
Change the default password of the Quagga/Zebra daemon and ensure that the password is changed whenever the appliance password is changed.