CVE-2026-6374: Hardcoded Credentials in Zyxel WAH7601 Router
Published Aug 10, 2026
·Updated
Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable.
This issue affects WAH7601: through 20.07.2026.
Affected Software
1 affected component
Zyxel Networks WAH7601 Router<=20.07.2026
Event History
Aug 10, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-6374?
CVE-2026-6374 has a severity rating of high, with a score of 7.3.
2
How do I fix CVE-2026-6374?
To mitigate CVE-2026-6374, it is recommended to replace the router or ensure it is updated to the latest firmware with no hardcoded credentials.
3
What devices are affected by CVE-2026-6374?
CVE-2026-6374 specifically affects the Zyxel WAH7601 router.
4
What are the potential risks associated with CVE-2026-6374?
The vulnerabilities in CVE-2026-6374 can lead to unauthorized access to sensitive information due to hardcoded credentials.
5
Is CVE-2026-6374 still exploitable?
Yes, CVE-2026-6374 remains exploitable until appropriate mitigation measures, such as firmware updates, are applied.