ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/489009/100/0/threaded | mailing list vdb entry third party advisory broken link |
http://www.gnucitizen.org/projects/router-hacking-challenge/ | broken link |
http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf | broken link |