CVE-2020-15316
Description
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zyxel CloudCNM SecuManager 3.1.0/3.1.1 ships a hardcoded ECDSA SSH key for root, enabling man-in-the-middle attacks and traffic decryption.
Vulnerability
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 (released November 14, 2018) contain a hardcoded ECDSA SSH key for the root account, stored within the /opt/axess chroot directory tree [1]. This key is used by the SSH server and is identical across all installations, meaning any attacker who obtains the key can impersonate the server or the client during SSH handshake.
Exploitation
An attacker with network access to the SSH service of a vulnerable Zyxel CloudCNM SecuManager can perform a man-in-the-middle (MITM) attack [1]. By placing themselves between the legitimate client and server, the attacker can present the known hardcoded host key to the client, intercept the encrypted session, and decrypt the SSH traffic. This requires no authentication or user interaction beyond the client accepting the unchanged host key fingerprint.
Impact
A successful MITM attack allows the attacker to capture all data transmitted over the SSH session, including login credentials, configuration commands, and other sensitive information [1]. The attacker may also inject malicious commands if the session is interactive or if automated scripts rely on the SSH connection. This compromises the confidentiality and integrity of the management traffic for the network management appliance.
Mitigation
Zyxel has not released a public patch for this specific vulnerability as of the publication date [1]. Administrators should restrict SSH access to trusted networks only, use VPN tunnels for remote management, and monitor for unauthorized SSH connections. The affected appliance also suffers from numerous other critical vulnerabilities, so isolating and replacing it is strongly recommended. No KEV listing exists for this CVE.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zyxel/CloudCNM SecuManagerdescription
- Range: 3.1.0, 3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.htmlmitrex_refsource_MISC
- www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.