Executive brief
The Zyxel WRE6505 v2, a wireless range extender used to expand WiFi coverage, contains a security flaw in its web management interface. This vulnerability allows an attacker on the same local network to repeatedly guess passwords without being locked out, potentially leading to unauthorized access to the device's settings. Because this product has reached its end-of-life, the manufacturer is not providing a security patch, and users are encouraged to upgrade to a supported model.
Technical details
An improper restriction of excessive authentication attempts (CWE-307) exists in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0. An adjacent attacker on the local area network (LAN) can perform a brute-force attack against the administrative password without triggering rate-limiting or lockout mechanisms. Successful exploitation allows the attacker to bypass authentication and gain administrative control over the device. This vulnerability is marked as 'Unsupported When Assigned' because the product has reached its End of Life (EOL) status, and no official patch is expected.
Affected products
- Zyxel WRE6505 v2 V1.00(ABDV.3)C0
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: NVD publication date