CVE-2026-6374
7.3Zyxel Networks · WAH7601
Zyxel Networks WAH7601 contains a hard-coded credentials vulnerability that allows an attacker to read sensitive constants within the device executable.
Executive summary
The Zyxel Networks WAH7601 is vulnerable to a hard-coded credentials flaw that poses a high risk of unauthorized information disclosure and system compromise.
Vulnerability
This vulnerability involves the use of hard-coded credentials within the device firmware, which allows an unauthenticated attacker on the local network to access sensitive constants. The attack vector is restricted to adjacent network access, requiring interaction from a user.
Business impact
The presence of hard-coded credentials significantly undermines the security posture of the affected device. Given the CVSS score of 7.3, this high-severity flaw could lead to the exposure of sensitive configuration data or administrative secrets, potentially allowing an attacker to gain further control over the network infrastructure. Such compromises often result in unauthorized access to internal communications and potential long-term persistence within the environment.
Remediation
Immediate Action: Organizations should apply the latest security updates provided by Zyxel Networks to remove the hard-coded credentials. If an update is not immediately available, restrict network access to the device to trusted segments only.
Proactive Monitoring: Security teams should monitor network traffic for anomalous access attempts targeting the device administration interfaces. Reviewing device logs for unauthorized authentication events is strongly advised.
Compensating Controls: Deploying network segmentation to isolate the WAH7601 from critical internal segments can mitigate the impact of this adjacent-network vulnerability. Web Application Firewalls or intrusion detection systems should be configured to flag suspicious management access patterns.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability represents a significant security risk due to the nature of hard-coded credentials, which are easily exploited if discovered. IT administrators must prioritize the application of vendor-supplied firmware updates to remediate this issue. Until patching is completed, ensure the device is not accessible from untrusted or public network segments to minimize exposure.