vendor:
by:
Koorosh Ghorbani
7.5
CVSS
HIGH
Denial of Service (DoS)
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Hardware
2015
ZYXEL remote configuration editor / Web Server DoS
ZYXEL Embedded Software does not check Cookies And Credentials on POST method so attackers could changes settings and view pages with post method. Sending empty Post to admin pages will crash internal web server and router needs to hard reset.