Description: - An issue discovered on Zyxel NBG-418N v2 device with firmware version V1.00(AARP.9)C0. can be accessed directly without authentication, leading to information disclosure and potential attack vectors. Vulnerability Type: - Incorrect Access Control Vendor of Product: - Zyxel Affected Product Code Base: - NBG-418N v2 - V1.00(AARP.9)C0 Attack Type: - Remote Impact: - Denial of Service => true - Information Disclosure => true Attack Vectors: - WAN configuration page "wan.htm" can be accessed directly without authentication, leading to WAN settings information disclosure and potential misuse of page data fields. CVE Reference: - CVE-2019-17354 Credits: - Found by Devendra Singh Solanki (https://twitter.com/_d0x0_)