VYPR
Unrated severityNVD Advisory· Published Jun 29, 2020· Updated Aug 4, 2024

CVE-2020-15316

CVE-2020-15316

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zyxel CloudCNM SecuManager 3.1.0/3.1.1 ships a hardcoded ECDSA SSH key for root, enabling man-in-the-middle attacks and traffic decryption.

Vulnerability

Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 (released November 14, 2018) contain a hardcoded ECDSA SSH key for the root account, stored within the /opt/axess chroot directory tree [1]. This key is used by the SSH server and is identical across all installations, meaning any attacker who obtains the key can impersonate the server or the client during SSH handshake.

Exploitation

An attacker with network access to the SSH service of a vulnerable Zyxel CloudCNM SecuManager can perform a man-in-the-middle (MITM) attack [1]. By placing themselves between the legitimate client and server, the attacker can present the known hardcoded host key to the client, intercept the encrypted session, and decrypt the SSH traffic. This requires no authentication or user interaction beyond the client accepting the unchanged host key fingerprint.

Impact

A successful MITM attack allows the attacker to capture all data transmitted over the SSH session, including login credentials, configuration commands, and other sensitive information [1]. The attacker may also inject malicious commands if the session is interactive or if automated scripts rely on the SSH connection. This compromises the confidentiality and integrity of the management traffic for the network management appliance.

Mitigation

Zyxel has not released a public patch for this specific vulnerability as of the publication date [1]. Administrators should restrict SSH access to trusted networks only, use VPN tunnels for remote management, and monitor for unauthorized SSH connections. The affected appliance also suffers from numerous other critical vulnerabilities, so isolating and replacing it is strongly recommended. No KEV listing exists for this CVE.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.