ZEXELON ZWX-2000CS Series Hard-Coded Credentials Vulnerability

Vulnerability

A vulnerability exists in ZEXELON ZWX-2000CSW2-HN firmware versions prior to 0.3.19 and in all versions of the ZWX-2000CS2-HN firmware. This vulnerability involves the use of hard-coded credentials, which, if exploited, could allow an attacker to manipulate the device's settings. The issue arises from an inadequate resolution of a previous vulnerability, CVE-2024-39838.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in the device's configuration.

Remediation

Users of the ZWX-2000CSW2-HN model should update the firmware to version 0.3.19 or later and consult the latest Wi-Fi settings manual and the coaxial login password/IP address change instructions available from the developer. For ZWX-2000CS2-HN users, it is recommended to check and modify the settings according to the developer's guidance. If difficulties arise in changing the settings, contact ZEXELON support.

Added: Jul 16, 2025, 5:18 AM
Updated: Jul 16, 2025, 5:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
3.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.