The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system. Furthermore, an attacker can start the device's TELNET service as a backdoor.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.slideshare.net/secret/qrHwDOJ71eLg7f |     | 
History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2018-04-01T18:00:00
Updated: 2024-08-05T07:17:51.468Z
Reserved: 2018-03-30T00:00:00
Link: CVE-2018-9149
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2018-04-01T18:29:00.287
Modified: 2024-11-21T04:15:04.850
Link: CVE-2018-9149
 Redhat
                        Redhat
                    No data.