The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Apr 9, 2025
Description
Published by the National Vulnerability Database
Mar 10, 2008
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Apr 9, 2025
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
References