Impact
The vulnerability allows an attacker to expose sensitive system information by performing web application fingerprinting on the Zyxel WAH7601 router. This disclosure can reveal configuration details and system internals that are not intended to be publicly available, potentially facilitating further exploitation. The weakness corresponds to CWE-497, which involves improper restriction of sensitive information disclosure.
Affected Systems
The issue affects Zyxel Networks WAH7601 routers through firmware version 20072026. No other vendor or product versions are listed, so the scope is limited to this specific router model and indicated firmware release.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability represents a moderate severity level. The EPSS score is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based, targeting the router's web administration interface, as the description mentions fingerprinting abilities. Since no exploitation path is described, it is presumed that administrative credentials or unauthenticated access to the web interface are required.
OpenCVE Enrichment