EIP-2026-102145

PRE-CVE

ZYXEL Prestig P-660HNU-T1 - ISP Credentials Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102145. PoCs published by Sebastián Magof.

AI-analyzed exploit summary This Perl script exploits an information disclosure vulnerability in ZyXEL Prestige P-660HNU-T1 routers by fetching the ISP username and password from the vulnerable 'wzADSL.asp' CGI endpoint. It uses LWP::UserAgent to send an HTTP GET request and extracts credentials via regex.

Description

ZYXEL Prestig P-660HNU-T1 - ISP Credentials Disclosure

Exploits (1)

exploitdb WORKING POC
by Sebastián Magof · perlwebappshardware
https://www.exploit-db.com/exploits/34751

This Perl script exploits an information disclosure vulnerability in ZyXEL Prestige P-660HNU-T1 routers by fetching the ISP username and password from the vulnerable 'wzADSL.asp' CGI endpoint. It uses LWP::UserAgent to send an HTTP GET request and extracts credentials via regex.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ZyXEL Prestige P-660HNU-T1 v2.00(AAIJ.1)
No auth needed
Prerequisites: Local network access to the router's default gateway (192.168.1.1)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026