VYPR
Unrated severityNVD Advisory· Published Jun 29, 2020· Updated Aug 4, 2024

CVE-2020-15318

CVE-2020-15318

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zyxel CloudCNM SecuManager 3.1.0/3.1.1 ships a hardcoded DSA SSH key for root inside the /opt/mysql chroot, enabling man-in-the-middle attacks.

Vulnerability

Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 contain a hardcoded DSA SSH key for the root account, located within the /opt/mysql chroot directory tree. The appliance uses this fixed key by default, and it is not regenerated during installation [1].

Exploitation

An attacker positioned on the network can perform a man-in-the-middle (MITM) attack against SSH connections to the affected appliance. Because the private key is known and static, the attacker can impersonate the server or decrypt captured SSH traffic without authentication or user interaction beyond the normal SSH handshake [1].

Impact

Successful exploitation results in loss of confidentiality and integrity of SSH-protected communications. The attacker can intercept credentials, configuration data, or other sensitive information transmitted over SSH sessions, and can inject or modify traffic as part of the MITM attack [1].

Mitigation

Zyxel has not released a patch as of the advisory date. The affected product is end-of-life (EOL). The only recommended mitigation is to decommission and replace the appliance with a supported alternative, or to isolate it from untrusted networks [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.