SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-45439

An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the device by leveraging another known vulnerability.

MEDIUM 6.5EPSS 0.20%

Does this matter?

Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.

Description

A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the device by leveraging another known vulnerability.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.20% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-312
Affected
zyxel/ax7501-b0 firmware
Source
security@zyxel.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.