vendor:
642R-11
by:
RafaleX
8.3
CVSS
HIGH
Denial of service
400
CWE
Product Name: 642R-11
Affected Version From: ZyXEL 642R-11
Affected Version To: Prestige 310
Patch Exists: YES
Related CWE: Bugtraq ID 3346
CPE: h:zyxel:642r-11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
ZyXEL telnet service DoS
ZyXEL 642R routers have difficulties handling certain types of malformed packets. In particular, it is possible to deny services by sending a vulnerable router a SYN-ACK packet. To a lesser degree, the router also encounters difficulties when handling SYN-FIN packets. In both instances, some services provided by the router (telnet, FTP and DHCP) will be denied, however, the device will continue to route network traffic. This issue has also been reproduced with other types of malformed packets.
Mitigation:
Apply the latest security patches and updates to the ZyXEL 642R router.