CVE-2008-1526

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
26/03/2008
Last modified:
09/04/2025

Description

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:p-663hn-51_firmware:*:*:*:*:*:*:*:* 3.40\(agd.2\) (including) 3.40\(ahq.3\) (including)
cpe:2.3:o:zyxel:p-663hn-51_firmware:3.40\(pe9\):*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p-663hn-51:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:p-660h-61_firmware:*:*:*:*:*:*:*:* 3.40\(agd.2\) (including) 3.40\(ahq.3\) (including)
cpe:2.3:o:zyxel:p-660h-61_firmware:3.40\(pe9\):*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p-660h-61:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:p-660h-63_firmware:*:*:*:*:*:*:*:* 3.40\(agd.2\) (including) 3.40\(ahq.3\) (including)
cpe:2.3:o:zyxel:p-660h-63_firmware:3.40\(pe9\):*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p-660h-63:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:p-660h-67_firmware:*:*:*:*:*:*:*:* 3.40\(agd.2\) (including) 3.40\(ahq.3\) (including)
cpe:2.3:o:zyxel:p-660h-67_firmware:3.40\(pe9\):*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p-660h-67:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:p-660h-d1_firmware:*:*:*:*:*:*:*:* 3.40\(agd.2\) (including) 3.40\(ahq.3\) (including)
cpe:2.3:o:zyxel:p-660h-d1_firmware:3.40\(pe9\):*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p-660h-d1:-:*:*:*:*:*:*:*