Loading
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.
Use CWE-798, Billion vendor hub and 5200w-T Firmware product page to widen CVE-2017-18374 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-18368, CVE-2017-18371 and CVE-2017-18369 for nearby disclosures in the same product family.