VYPR
Critical severity9.8NVD Advisory· Published Dec 31, 2015· Updated May 6, 2026

CVE-2015-6016

CVE-2015-6016

Description

ZyXEL P-660HW-T1, PMG5318-B20A, and NBG-418N routers ship with a default admin password of '1234', allowing remote attackers full administrative access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ZyXEL P-660HW-T1, PMG5318-B20A, and NBG-418N routers ship with a default admin password of '1234', allowing remote attackers full administrative access.

Vulnerability

Several ZyXEL router models ship with a weak default password of 1234 for the admin account. The affected devices include the ZyXEL P-660HW-T1 v2 running ZyNOS firmware version V3.40(AXH.0) (dated 3/30/2007), the ZyXEL PMG5318-B20A with firmware version V100AANC0b5, and the ZyXEL NBG-418N. Many additional models have been reported to share the same default credential [1][2].

Exploitation

An attacker with network access to the router's management interface (typically the web-based administration panel) can simply log in using the username admin and the password 1234. No authentication bypass or additional privileges are required. The default password is well-known and can be trivially guessed or obtained from public sources [1][2].

Impact

Successful exploitation grants the attacker full administrative control over the affected router. This allows the attacker to change device configuration, read or modify network settings, enable remote access, intercept traffic, and potentially pivot to internal network resources. The compromise is at the highest privilege level (admin) and can lead to complete loss of confidentiality, integrity, and availability of the device and connected networks [1][2].

Mitigation

ZyXEL has not released a firmware update to address this issue for the listed models, which may be end-of-life. The primary mitigation is to change the default password immediately upon device deployment. Users should set a strong, unique password for the admin account via the router's administration interface. Additionally, disabling remote management access or restricting it to trusted IP addresses reduces exposure. No official patch is available from the vendor [1][2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • Zyxel/Nbg 418n2 versions
    cpe:2.3:h:zyxel:nbg-418n:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:h:zyxel:nbg-418n:-:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:o:zyxel:pmg5318-b20a_firmware:v100aanc0b5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zyxel:pmg5318-b20a_firmware:v100aanc0b5:*:*:*:*:*:*:*
    • (no CPE)range: = firmware 1.00AANC0b5
  • cpe:2.3:o:zyxel:zynos_firmware:3.40\(axh.0\):*:*:*:*:*:*:*
  • Zyxel/P 660hwllm-create
    Range: = ZyNOS firmware 3.40(AXH.0)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.