CVE-2025-53842: Zexelon Co., Ltd Zwx-2000cs2-Hn
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838.
Affected products
- Zexelon Co., Ltd Zwx-2000cs2-Hn: any version
- Zexelon Co., Ltd Zwx-2000csw2-Hn: before 0.3.19 (fixed in 0.3.19)
Published 2025-07-16. Last modified 2026-06-17.