Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-1524 Details

Description

The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has "public" as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-16Configuration[email protected]

Affected Products

ProductVersions
zyxel prestige 660
h-d1
h-d3

CPE

  • cpe:2.3:h:zyxel:prestige_660:h-d1:*:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:prestige_660:h-d3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
zyxel prestige 661
hw-d1

CPE

  • cpe:2.3:h:zyxel:prestige_661:hw-d1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
zyxel zynos
3.40 agd.2
3.40 agl.3
3.40 ahq.0
3.40 ahq.3
3.40 ahz.0

CPE

  • cpe:2.3:h:zyxel:zynos:3.40:agd.2:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:zynos:3.40:agl.3:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:zynos:3.40:ahq.0:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:zynos:3.40:ahq.3:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:zynos:3.40:ahz.0:*:*:*:*:*:*
  • cpe:2.3:h:zyxel:zynos:3.40:atm.0:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-1524
NVD Published Date:
Mar 26, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-1524 Details - Not Deferred