CVE-2026-6374
Deferred Deferred - Pending Action

Hard-Coded Credentials in Zyxel WAH7601

Vulnerability report for CVE-2026-6374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-26

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-26
Generated
2026-08-30
AI Q&A
2026-08-10
EPSS Evaluated
2026-08-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zyxel wah7601 to 20.07.2026 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves hard-coded credentials in Zyxel Networks WAH7601 devices. Hard-coded credentials are sensitive login details embedded directly into the device's firmware or software, which can be exploited by attackers to gain unauthorized access.

Detection Guidance

Detection of hard-coded credentials in Zyxel WAH7601 requires manual inspection of firmware or configuration files. Check for default or embedded credentials in system files or network traffic. Use tools like strings, binwalk, or firmware analysis tools to search for plaintext passwords or API keys.

Impact Analysis

Attackers could exploit this to read sensitive data, modify device settings, or perform unauthorized actions. Since the credentials are hard-coded, they may be easily discoverable, increasing the risk of compromise for affected devices.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if such breaches occur due to inadequate security measures.

Mitigation Strategies

Update the Zyxel WAH7601 firmware to the latest version released after 20.07.2026 to remove hard-coded credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart