cve/2008/CVE-2008-1260.md
2025-09-29 21:09:30 +02:00

832 B

CVE-2008-1260

Description

Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.

POC

Reference

No PoCs from references.

Github