Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Wed, 16 Jul 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838. | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-07-16T04:30:36.624Z
Updated: 2025-07-18T14:47:09.380Z
Reserved: 2025-07-10T01:58:07.983Z
Link: CVE-2025-53842
Updated: 2025-07-18T14:47:06.400Z
Status : Awaiting Analysis
Published: 2025-07-16T05:15:33.900
Modified: 2025-07-16T14:58:59.837
Link: CVE-2025-53842
No data.