CVE-2026-12984
8.2Zyxel Networks · WAH7601
The Zyxel WAH7601 router contains an insufficiently protected credentials vulnerability that allows unauthenticated attackers to retrieve sensitive data.
Executive summary
A critical credential exposure vulnerability in Zyxel WAH7601 routers allows unauthenticated remote attackers to extract sensitive information, significantly risking network security.
Vulnerability
This vulnerability, CWE-522, involves insufficient protection of credentials within the device firmware. The attack vector is network-based and does not require authentication, allowing any remote user with network access to the device to potentially retrieve sensitive configuration data.
Business impact
The CVSS score of 8.2 underscores the high risk of unauthorized information disclosure. By obtaining embedded credentials, an attacker could gain administrative access to the router, facilitating further network attacks, traffic interception, or total control over the gateway device, resulting in severe reputational and operational damage.
Remediation
Immediate Action: Check the Zyxel support website for firmware updates and apply the latest version to the WAH7601 device immediately.
Proactive Monitoring: Monitor device logs for unauthorized login attempts and inspect network traffic for unusual administrative access requests.
Compensating Controls: Isolate the management interface of the router from the public internet using firewall rules or VPN-only access to prevent remote exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly critical due to its unauthenticated nature and the sensitivity of the exposed data. Administrators must prioritize updating the firmware on all WAH7601 units and ensure that management interfaces are restricted to prevent external exposure while awaiting or applying patches.