Sceawere

Vulnerability Detail

CVE-2026-12984UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zyxel WAH7601 Credential Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
2h ago
Vendor
Zyxel Networks
Product
WAH7601
Attack Type
CWE-522 Insufficiently Protected Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: through 20072026.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-10T13:17:55.887Z",
  "pubdate": "2026-08-10T13:17:55.887Z",
  "executiveSummary": "An insufficiently protected credentials vulnerability has been identified in the Zyxel Networks WAH7601 mobile hotspot product. This security flaw enables unauthorized actors to retrieve embedded sensitive data, potentially exposing critical authentication secrets and administrative access material.\nThe vulnerability directly impacts the Zyxel Networks WAH7601 device running firmware versions up to and including 20072026. The risk implications are severe, as unauthorized exposure of administrative or user credentials compromises the confidentiality and integrity of the device management plane.\nExploitation of this vulnerability typically requires an attacker to interact with the vulnerable component, either locally or remotely depending on the exposure of the management interface, to extract the insecurely stored or transmitted sensitive data. No complex attacker capabilities are required beyond the ability to query or access the vulnerable credential storage mechanism.\nSuccessful exploitation allows unauthorized retrieval of sensitive material, which can subsequently be leveraged to conduct further unauthorized actions, escalate privileges, or facilitate complete device compromise within the affected operational environment.",
  "technicalDetails": "The root cause of this vulnerability stems from inadequate protection mechanisms applied to sensitive credentials stored within the Zyxel Networks WAH7601 firmware. Specifically, the affected component fails to enforce proper encryption, obfuscation, or access control restrictions on embedded authentication data, leaving them accessible to unauthorized entities.\nThe vulnerable component involves the internal configuration storage or data retrieval routines responsible for handling embedded sensitive data within the device firmware. Affected versions comprise all releases of the WAH7601 product through firmware version 20072026.\nThe step-by-step attack flow typically proceeds as follows: First, the threat actor identifies the target Zyxel Networks WAH7601 device and determines the accessibility of the interface or mechanism responsible for exposing configuration data or embedded strings. Second, the attacker interacts with the vulnerable endpoint or mechanism without possessing the necessary administrative authorization. Third, the targeted component processes the request and improperly returns the embedded sensitive data in plaintext or weakly encoded formats. Finally, the attacker harvests the retrieved credentials for subsequent unauthorized authentication or lateral movement.\nDepending on network exposure and service configurations, exploitation may occur over the local network interface or remote management interfaces exposed by the device. The payload behavior centers on the extraction of static or dynamic secrets, enabling post-exploitation impact such as unauthorized administrative session establishment, configuration tampering, and full device takeover."
}
CVE-2026-12984: Zyxel WAH7601 Credential Disclosure Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere