Collected research
SNMP XSS Attack
ProCheckUp's ZyXEL Prestige gateway research. SNMP write is on by default with community string 'public', so snmpset into system.sysName.0 stores a 32-character persistent XSS that fires in the admin web interface. Also covers guest-to-admin URL privilege escalation, IP-only session management, unsalted MD5 replay, cleartext WEP/PPPoE/DDNS credentials and remote wardriving.
Record
- Researcher
- Adrian Pastor
- Published by
- procheckup.com
- Format
- Whitepaper
- Topic
- XSS
In the archive
Related sources
- ZyXEL Gateways Vulnerability Research: multiple vulnerabilities including privilege escalation, insecure SNMP permissions, session hijacking, weak authentication and disclosure of credentials
- ProCheckUp - Penetration Testing, PCI DSS Compliance, Application Testing
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Pastor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .