VYPR
Unrated severityNVD Advisory· Published Jun 29, 2020· Updated Aug 4, 2024

CVE-2020-15312

CVE-2020-15312

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hardcoded DSA SSH key in Zyxel CloudCNM SecuManager 3.1.0/3.1.1 allows man-in-the-middle attacks.

Vulnerability

Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 contain a hardcoded DSA SSH key for the root account, which is used for SSH server authentication on the main host and within chroot environments [1]. The key is embedded in the appliance's filesystem, and no per-device key generation occurs during initial setup.

Exploitation

An attacker who can intercept network traffic between a client and the SecuManager appliance can perform a man-in-the-middle attack. Because the private key is identical across all instances, the attacker can impersonate the server to any connecting SSH client, decrypting and potentially modifying the session. No prior authentication or special privileges are required beyond network proximity.

Impact

Successful exploitation allows the attacker to decrypt all SSH traffic, revealing credentials, configuration data, and other sensitive information transmitted over the management channel. The attacker could also inject malicious commands into the session, potentially gaining full control over the appliance [1].

Mitigation

As of the available references, Zyxel has not released a fixed version for the CloudCNM SecuManager. Users should restrict network access to the management interface to trusted hosts only, use VPNs or encrypted tunnels for remote access, and consider migrating to a supported alternative [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.