CVE-2017-7964: Zyxel WRE6505 Firmware

Critical severity, CVSS 10.0. EPSS: 2.5% chance of exploitation in the next 30 days.

Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.

Affected products

  • Zyxel WRE6505 Firmware: up to and including v1.00\(aaqb.3\)c0

Published 2017-04-19. Last modified 2026-06-17.