CVE-2018-18754: Zyxel VMG3312-b10b Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

Affected products

  • Zyxel VMG3312-b10b Firmware: version 1.00(aapp.7) only

Published 2018-10-29. Last modified 2026-06-17.