CVE-2023-22920: Zyxel LTE3202-m437 Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.

Affected products

  • Zyxel LTE3202-m437 Firmware: version 1.00(abwf.1)c0 only
  • Zyxel LTE3316-m604 Firmware: version 2.00(abmp.6)c0 only

Published 2023-02-21. Last modified 2026-06-17.