vendor:
PK5001Z
by:
Matthew Sheimo
8,8
CVSS
HIGH
Hardcoded Password
798
CWE
Product Name: PK5001Z
Affected Version From: PK5001Z 2.6.20.19
Affected Version To: PK5001Z 2.6.20.19
Patch Exists: NO
Related CWE: CVE-2016-10401
CPE: h:zyxel:pk5001z
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
ZyXEL PK5001Z Modem – CenturyLink Hardcoded admin and root Telnet Password
ZyXEL PK5001Z Modem is used by Century Link a global communications and IT services company focused on connecting its customers to the power of the digital world. The modem has a hardcoded admin and root Telnet password which can be used to login via Telnet. The admin username is 'admin' and the password is 'CenturyL1nk'. The root password is 'zyad5001'.
Mitigation:
The user should change the default password of the modem and should not use the hardcoded password.