← Vulnerability feed

Vulnerability record · CVE-2015-6016 · published 31 December 2015

CVE-2015-6016: Zyxel nbg-418n vulnerability

Zyxel · Nbg 418n

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.

9.8 CVSS 3.0 Critical EPSS 5.7% · top 7.2% CWE-255 · CWE-255
9.8CVSS 3.0 base score, v2 10.0
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-6018Zyxel pmg5318-b20a firmware permissions and access controls vulnerabilityThe diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary com…EPSS 21%8.5CVE-2015-6019Zyxel pmg5318-b20a firmware vulnerabilityThe management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote a…EPSS 3.0%8.0CVE-2015-7284Zyxel nbg-418n firmware cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authenti…EPSS 1.1%8.0CVE-2015-6020Zyxel pmg5318-b20a firmware permissions and access controls vulnerabilityZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the…EPSS 2.2%5.9CVE-2015-7256Zyxel nwa1100-n firmware vulnerabilityZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, …EPSS 0.79%8.8CVE-2014-1812Microsoft Windows Group Policy Preferences credential exposure and privilege escalationGroup Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any auth…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2015-6016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.