CVE-2020-15334
Description
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zyxel CloudCNM SecuManager 3.1.0/3.1.1 logs attacker-controlled data to /var/log/axxmpp.log without sanitization, enabling escape-sequence injection.
Vulnerability
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 contain an escape-sequence injection vulnerability in the file /var/log/axxmpp.log. The xmppCnrSender.py script logs input from the XMPP connection manager without proper sanitization, allowing an attacker to inject ANSI escape sequences into the log file [1].
Exploitation
An attacker with network access to the SecuManager's management interface can send crafted XMPP messages containing escape sequences. These sequences are then written verbatim to the log file. No authentication is required for this injection, as the XMPP channel is accessible without credentials by default [1].
Impact
When an administrator views the log file (e.g., via cat, less, or a log viewer that interprets escape sequences), the injected sequences can execute arbitrary terminal commands, potentially leading to information disclosure or further compromise of the admin's session. The impact depends on the terminal emulator and viewer software used [1].
Mitigation
Zyxel has not released a patch for this vulnerability as of the publication date (2020-06-26). The product may be end-of-life; users should restrict network access to the SecuManager and avoid viewing logs with terminal emulators that interpret escape sequences [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zyxel/CloudCNM SecuManagerdescription
- Range: 3.1.0, 3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.htmlmitrex_refsource_MISC
- www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.