CVE-2015-6016

CRITICAL

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows ...

Affects 4 products across 1 vendor.

BCS7.64
CVSS 3.09.8
EPSS5.7%
Percentile93th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-255: CWE-255
◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2015. A critical vulnerability affects Zyxel systems (CVE-2015-6016). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2015-GLOBAL-259860-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-6016?
This vulnerability was disclosed in 2015. A critical vulnerability affects Zyxel systems (CVE-2015-6016). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2015-6016?
CVE-2015-6016 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 5.7%.
Is CVE-2015-6016 actively exploited?
No confirmed active exploitation of CVE-2015-6016 as of 2026-09-25.
How do I remediate CVE-2015-6016?
Priority: MEDIUM.
What systems are affected by CVE-2015-6016?
CVE-2015-6016 affects: Zyxel, Zyxel, Zyxel, Zyxel.
Vulnerability Details
CVE IDCVE-2015-6016
BSIDBS-2015-GLOBAL-259860-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2015-12-31
Last Modified2026-06-17
ICS Relevance75%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Zyxel Nbg-418N —
Zyxel P-660Hw-T1 2 —
Zyxel Zynos Firmware —
Zyxel Pmg5318-B20A Firmware —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 3924 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash025da9ad1e00be7cbf7b9fb3b583385d24727eb7a24de1e93d135f6496c678b5a2d4ae8eba8076f664bb0d68e0ecf4d780ba761a02a9241f71d0341f15dfe1fe
Related CVEs affecting Zyxel
CVE-2017-7964 10.0 Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and... CVE-2008-1256 10.0 The ZyXEL P-660HW series router has "admin" as its default password, which al... CVE-2008-1255 10.0 The ZyXEL P-660HW series router maintains authentication state by IP address,... CVE-2015-6018 9.8 The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmwar... CVE-2008-1160 9.8 ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processe...
View all Zyxel CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →