CVE-2017-7964 describes a critical vulnerability in Zyxel WRE6505 devices, where default TELNET credentials ("1234" for root and admin accounts) allow remote attackers to reconfigure the built-in dnshijacker process, leading to DNS hijacking. This vulnerability has a CVSS score of 10.0 (CRITICAL), indicating a network-attackable, low-complexity exploit with no user interaction required, resulting in complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= v1.00\(aaqb.3\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:wre6505_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.