Executive brief
A security vulnerability exists in the Zyxel WRE6505 v2 WiFi extender, a device used to expand wireless network coverage. An attacker with administrative access to the device can download and decrypt the system's backup configuration file. This could lead to the exposure of sensitive settings or credentials stored within the device configuration.
Technical details
The Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 suffers from an insecure storage vulnerability (CWE-922) within its configuration management component. The vulnerability allows a local attacker who has already obtained high-privilege (administrator) access to extract and decrypt the backup configuration file. This occurs because the sensitive information within the configuration file is not sufficiently protected against decryption by authorized local users. As the product is marked as 'Unsupported When Assigned,' no official patch is expected, and users are encouraged to follow Zyxel's end-of-life migration paths.
Affected products
- Zyxel WRE6505 v2 firmware V1.00(ABDV.3)C0
Timeline
- 2026-05-12: disclosed: Initial publication of the CVE record