VYPR
Unrated severityNVD Advisory· Published Jun 29, 2020· Updated Aug 4, 2024

CVE-2020-15322

CVE-2020-15322

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2020-15322 results from a hardcoded password (wbboEZ4BN3ssxAfM) for the debian-sys-maint MySQL account in Zyxel CloudCNM SecuManager, enabling attackers to gain unauthorized database access.

Vulnerability

The vulnerability resides in Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1. The MySQL database contains a hardcoded password, wbboEZ4BN3ssxAfM, for the debian-sys-maint account [1]. This account is typically used for system maintenance tasks but because the password is identical across installations, it cannot be changed without external tooling, and there is no mechanism to disable it [1].

Exploitation

An attacker with network access to the SecuManager server can connect to the MySQL service (likely on the default port 3306) and authenticate as debian-sys-maint using the known password [1]. No other credentials or prior compromise are necessary. The attacker may then execute arbitrary SQL queries against the MySQL instance.

Impact

Successful authentication as debian-sys-maint grants full read and write access to the MySQL database underlying the SecuManager application. This could allow an attacker to extract sensitive configuration data, user credentials, or network topology information, and potentially modify database content to compromise the integrity of the management system [1].

Mitigation

As of the publication date (2020-06-29), Zyxel had not released a fixed version. Users are advised to restrict network access to the MySQL port (3306) to only trusted administrative hosts via firewall rules, and to monitor for any unauthorized database connections. The vendor has not announced an end-of-life status for this product in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.