CVE-2026-12984 Overview
CVE-2026-12984 is an Insufficiently Protected Credentials vulnerability [CWE-522] affecting the Zyxel Networks WAH7601 mobile router. The flaw allows a remote attacker to retrieve embedded sensitive data from the device without authentication. The issue affects WAH7601 firmware through version 20072026. Successful exploitation exposes credentials that can be used for follow-on attacks against the device and its connected network. The vulnerability was published to the National Vulnerability Database (NVD) on August 10, 2026.
Critical Impact
Remote unauthenticated attackers can retrieve embedded credentials from affected Zyxel WAH7601 routers, enabling device takeover and potential lateral movement into connected networks.
Affected Products
- Zyxel Networks WAH7601 (all firmware through 20072026)
- Portable LTE mobile router product line
- Deployments exposing device management interfaces to untrusted networks
Discovery Timeline
- 2026-08-10 - CVE-2026-12984 published to NVD
- 2026-08-10 - Last updated in NVD database
- 2026-08-13 - EPSS score published at 0.255%
Technical Details for CVE-2026-12984
Vulnerability Analysis
The vulnerability resides in how the Zyxel WAH7601 stores and protects sensitive credentials within its firmware or configuration surface. An attacker on the network can reach an interface that returns embedded credential material without proper authentication or protection. The weakness is categorized under CWE-522 (Insufficiently Protected Credentials), which covers scenarios where authentication data is transmitted or stored using a method susceptible to unauthorized interception or retrieval. The attack requires no user interaction and no prior privileges on the target device.
Root Cause
The root cause is the storage or exposure of credentials in a form that is not adequately protected against retrieval. Embedded sensitive data on the WAH7601 is reachable through a network-accessible path that does not enforce sufficient access controls or cryptographic protection. Devices running firmware versions through 20072026 are affected.
Attack Vector
The attack vector is network-based with low complexity. An unauthenticated remote attacker sends crafted requests to the affected device and extracts sensitive credential data. The retrieved credentials can then be used to authenticate to management interfaces, pivot into the connected local network, or reuse credentials against other services if they were reused. Refer to the Siber Güvenlik Notification TR-26-0799 for additional context. Verified exploitation code is not published in the referenced advisory.
Detection Methods for CVE-2026-12984
Indicators of Compromise
- Unexpected inbound HTTP or HTTPS requests to WAH7601 management interfaces from external or unusual internal sources
- Access log entries showing retrieval of configuration, backup, or credential-related endpoints without prior authentication
- Anomalous authenticated sessions to the device or upstream services shortly after unauthenticated probes
Detection Strategies
- Inspect network traffic to router management ports for unauthenticated requests targeting configuration or credential endpoints
- Correlate device access logs with subsequent authentication events on downstream systems to identify credential replay
- Alert on WAH7601 firmware versions at or below 20072026 discovered on the network through asset inventory scans
Monitoring Recommendations
- Monitor for outbound connections from the router to unknown destinations that may indicate command-and-control activity
- Track administrative logins to WAH7601 devices and flag logins from new source addresses
- Log DNS and DHCP anomalies on networks served by the affected router that may signal compromise
How to Mitigate CVE-2026-12984
Immediate Actions Required
- Identify all Zyxel WAH7601 devices in the environment and confirm firmware version
- Restrict access to device management interfaces to trusted management networks only
- Rotate any credentials that may have been stored on or reachable through the affected device
Patch Information
Zyxel Networks has not published a fixed firmware version in the referenced advisory at the time of NVD publication. Monitor the Siber Güvenlik Notification TR-26-0799 and the Zyxel security advisory portal for firmware updates addressing CVE-2026-12984. Apply updated firmware as soon as the vendor releases a patched build superseding version 20072026.
Workarounds
- Block untrusted network access to the router's HTTP, HTTPS, and remote management ports at the perimeter
- Disable remote management features on the WAH7601 if they are not required for operations
- Segment the WAH7601 onto a dedicated VLAN and restrict lateral traffic to and from the device
- Replace default and shared administrative credentials with unique, strong values on every affected unit
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

