CVE-2020-15344
Description
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zyxel CloudCNM SecuManager 3.1.0/3.1.1 exposes an unauthenticated API that leaks user IDs and API keys.
Vulnerability
CVE-2020-15344 describes an unauthenticated API endpoint zy_get_user_id_and_key in Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1. The API does not require any authentication or authorization, allowing any remote attacker to query it and obtain sensitive user identifiers and API keys directly from the management interface [1].
Exploitation
An attacker can send a crafted HTTP request to the zy_get_user_id_and_key endpoint without needing any prior credentials, network position, or user interaction. Since the appliance has no firewall by default and some daemons are WAN-reachable [1], exploitation can be performed from the internet by simply targeting the exposed management web server.
Impact
Successful exploitation leaks user IDs and API keys, which are credentials that can be reused to access further functionality within the SecuManager. This disclosure could lead to unauthorized management actions, further information gathering, or serve as a stepping stone for more severe attacks like remote code execution via other backdoor APIs [1].
Mitigation
Zyxel has not released a patch for this vulnerability as of the publication date (2020-06-26). The device remains vulnerable; users should restrict network access to the management interface, place it behind a firewall, and monitor for any vendor updates. The CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zyxel/CloudCNM SecuManagerdescription
- Range: = 3.1.0, = 3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.htmlmitrex_refsource_MISC
- www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.