PT-2024-28693 · Unknown · Zwx-2000Csw2-Hn

Hiroki Sato

·

Published

2024-08-05

·

Updated

2025-07-16

·

CVE-2024-39838

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15
Description The issue concerns the use of hard-coded credentials in the firmware, which may allow a network-adjacent attacker with administrative privilege to alter the device's configuration.
Recommendations For versions prior to Ver.0.3.15, update the firmware to Ver.0.3.15 or later to resolve the issue. As a temporary workaround, consider restricting administrative access to the device until the update can be applied.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-39838

Affected Products

Zwx-2000Csw2-Hn