Sceawere
Vulnerability Detail
CVE-2026-6373UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zyxel WAH7601 Information Exposure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- Zyxel Networks
- Product
- WAH7601
- Attack Type
- CWE-497 Exposure of sensitive system information to an unauthorized control sphere
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-10T13:20:38.220Z",
"pubdate": "2026-08-10T13:20:38.220Z",
"executiveSummary": "An exposure of sensitive system information to an unauthorized control sphere vulnerability exists within the Zyxel Networks WAH7601 product, specifically enabling Web Application Fingerprinting. This security flaw permits unauthorized remote entities to extract granular metadata and identifying characteristics regarding the underlying web application architecture and device firmware. The affected product is the WAH7601, encompassing firmware versions up to and including 20072026. The primary risk implication centers on reconnaissance capability, where an attacker can profile the target device to identify specific software versions, known vulnerabilities, and structural configurations. This intelligence significantly lowers the barrier for subsequent, highly targeted exploitation attempts against the device. The exploitation requirements involve network-based interaction with the exposed web interface, allowing unauthenticated attackers to query the system and harvest sensitive application fingerprints without requiring specialized privileges or complex payload delivery mechanisms.",
"technicalDetails": "The vulnerability stems from improper handling and excessive disclosure of system parameters and HTTP response headers within the web management interface of the Zyxel Networks WAH7601. Specifically, the web application exposes detailed platform identifiers, server banner information, and specific structural fingerprints that characterize the execution environment of the control sphere. The affected component is the embedded HTTP server and associated web application modules responsible for handling incoming client requests on the WAH7601. Affected versions include all firmware iterations up to 20072026. The root cause is rooted in inadequate abstraction and sanitization of server responses, allowing internal system metadata to leak directly to unauthenticated external entities across the network. The attack flow initiates when an adversary sends a standard HTTP request—such as a GET or HEAD method—to the exposed web service endpoints of the target device. In response, the vulnerable web application returns verbose headers, specific error pages, or predictable structural artifacts that uniquely identify the product model, firmware build, and underlying technology stack. Because the vulnerability requires no authentication or privilege escalation, any network-adjacent or remote actor capable of communicating with the device's management interface can execute this reconnaissance phase. The payload behavior is passive or active querying, requiring no complex execution flow or memory corruption primitives. The post-exploitation impact is strictly informational from the perspective of this specific flaw; however, the harvested web application fingerprint provides the attacker with precise reconnaissance data. This intelligence enables the adversary to cross-reference the exact WAH7601 version against known vulnerability databases, facilitating the selection of secondary exploits tailored to compromise the device's administrative control sphere completely."
}