CVE-2020-15321
Description
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 contains a hardcoded password 'axzyxel' for the livedbuser MySQL account, enabling remote database access.
Vulnerability
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 include a hardcoded password axzyxel for the livedbuser MySQL database account. This backdoor account is present in the MySQL configuration and allows unauthenticated access to the database without any special conditions or configuration changes [1].
Exploitation
An attacker with network access to the MySQL service (typically exposed on the management interface) can connect to the database using the known credentials: username livedbuser and password axzyxel. No prior authentication or user interaction is required. The attacker simply uses a MySQL client to log in [1].
Impact
Successful exploitation grants the attacker full read and write access to the MySQL database, which likely stores sensitive device configurations, credentials, and management data. This can lead to further compromise of the SecuManager appliance and managed devices [1].
Mitigation
No official fix has been released as of the publication date. The affected versions (3.1.0 and 3.1.1) remain vulnerable. Users should restrict network access to the MySQL service and monitor for unauthorized connections. If possible, upgrade to a patched version if one becomes available [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zyxel/CloudCNM SecuManagerdescription
- Range: 3.1.0, 3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.htmlmitrex_refsource_MISC
- www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.