Impact
The vulnerability is a hard‑coded credential flaw in the Zyxel WAH7601 router that permits an attacker to read sensitive constants from the firmware. Because the credentials are embedded in the executable, they enable authentication to the router’s management interface without valid user input. This weakness falls under CWE‑798 and can allow an adversary to modify configuration settings or monitor network traffic once authenticated.
Affected Systems
The affected product is the Zyxel Networks WAH7601 router. Firmware versions through 20.07.2026 contain the flaw. Although specific firmware revisions are not listed, any router running a firmware build before or on that date is vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate‑to‑high severity risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not documented, the presence of hard‑coded credentials suggests that an attacker who can reach the router’s management interface—whether via an exposed web, SSH, or CLI port—could use the embedded credentials to gain unauthorized access. The risk is elevated if remote management services are exposed to untrusted networks.
OpenCVE Enrichment