PT-2024-28693 · Unknown · Zwx-2000Csw2-Hn

·

CVE-2024-39838

·

Published

2024-08-05

·

Updated

2025-07-16

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15
Description The issue concerns the use of hard-coded credentials in the firmware, which may allow a network-adjacent attacker with administrative privilege to alter the device's configuration.
Recommendations For versions prior to Ver.0.3.15, update the firmware to Ver.0.3.15 or later to resolve the issue. As a temporary workaround, consider restricting administrative access to the device until the update can be applied.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39838

Affected Products

Zwx-2000Csw2-Hn