Impact
The vulnerability involves insufficiently protected credentials in Zyxel Networks WAH7601, allowing an attacker to retrieve embedded sensitive data. Because credentials are not adequately hidden or encrypted, anyone obtaining them can gain unauthorized access to confidential information stored on the device. This leads to a compromise of confidentiality, and attackers could use the information for further intrusion or malicious activities.
Affected Systems
This issue affects all Zyxel Networks WAH7601 devices with firmware versions through 20072026. No other vendors or products are mentioned.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS is currently not available so the exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation reports yet. The likely attack vector is that an attacker with network access to the management interface could exploit weak credential protections to read stored credentials or sensitive data. The attack requires the target device to be reachable and to present the vulnerable firmware; no advanced preconditions like privileged user credentials are explicitly required based on the description.
OpenCVE Enrichment