CVE-2008-1160

CRITICAL ⚠ Exploit

ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

Affects 2 products across 1 vendor.

BCS8.78
CVSS 3.19.8
EPSS14.8%
Percentile97th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-798: Use of Hard-Coded Credentials

Software contains embedded passwords or keys that cannot be changed by the administrator.

Related Attack Patterns (CAPEC)
CAPEC-70 Try Common or Default Usernames and Passwords
via CWE-798
CAPEC-191 Read Sensitive Constants Within an Executable
via CWE-798

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

ZyXEL ZyWALL 1050 devices contain a hard-coded password for the Quagga and Zebra processes that is not changed during user setup, allowing remote attackers to gain unauthorized privileges.

BSID: BS-2008-GLOBAL-241184-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-1160?
ZyXEL ZyWALL 1050 devices contain a hard-coded password for the Quagga and Zebra processes that is not changed during user setup, allowing remote attackers to gain unauthorized privileges.
What is the CVSS score for CVE-2008-1160?
CVE-2008-1160 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 14.8%.
Is CVE-2008-1160 actively exploited?
Public exploit available for CVE-2008-1160. Exploitation risk elevated.
How do I remediate CVE-2008-1160?
Priority: IMMEDIATE. Advisory: http://secunia.com/advisories/29237 PSIRT: [email protected]
What systems are affected by CVE-2008-1160?
CVE-2008-1160 affects: Zyxel, Zyxel.
Vulnerability Details
CVE IDCVE-2008-1160
BSIDBS-2008-GLOBAL-241184-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2008-03-25
Last Modified2026-06-16
ICS Relevance90%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by connecting to the affected device and using the hard-coded password to authenticate and gain access to the Quagga and Zebra processes, which can lead to full administrative control over the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Zyxel Zywall 1050 Firmware —
Zyxel Zywall 1050 —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 6761 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ Available — Reference
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Zyxel
CVE-2017-7964 10.0 Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and... CVE-2008-1256 10.0 The ZyXEL P-660HW series router has "admin" as its default password, which al... CVE-2008-1255 10.0 The ZyXEL P-660HW series router maintains authentication state by IP address,... CVE-2015-6018 9.8 The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmwar... CVE-2015-6016 9.8 ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devi...
View all Zyxel CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →