[Japanese]
|
JVNDB-2025-000049
|
ZWX-2000CSW2-HN and ZWX-2000CS2-HN vulnerable to use of hard-coded credentials
|
ZWX-2000CSW2-HN and ZWX-2000CS2-HN provided by ZEXELON CO., LTD. contain the following vulnerability.
* Use of Hard-coded Credentials (CWE-798) - CVE-2025-53842
This vulnerability is caused by an insufficient fix for CVE-2024-39838 (JVN#70666401).
Hiroki Sato of Institute of Science Tokyo reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 4.5 (Medium) [IPA Score]
- Attack Vector: Adjacent Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
|
|
ZEXELON CO., LTD.
- ZWX-2000CS2-HN firmware all versions
- ZWX-2000CSW2-HN firmware versions prior to 0.3.19
|
|
An attacker may tamper with the settings of the device by obtaining the credentials.
|
ZWX-2000CSW2-HN
[Update the firmware]
Update the firmware to the latest version and check and change the settings according to the information provided by the developer.
ZWX-2000CS2-HN
[Apply the workaround]
Check and change the settings according to the information provided by the developer.
|
ZEXELON CO., LTD.
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2025-53842
|
- JVN : JVN#70666401
- JVN : JVN#44419726
|
- [2025/07/16]
Web page was published
|