Summary
The remote Router is prone to the 'rom-0' Vulnerability
Impact
Attackers can exploit this issue to bypass certain security restrictions and obtain sensitive information which may aid in further attacks.
Solution
Ask the Vendor for an update.
Insight
If you request the /rom-0 file it does not require authentication. This can be reversed using available tools like the one at http://50.57.229.26/zynos.php. The first string returned is the admin password.
Detection
Request /rom-0 and check the response.
References