CVE-2026-7257
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.11%
- CWE
- CWE-922
- Published
- 2026-05-12
- Last modified
- 2026-05-12
Affected products
- Zyxel WRE6505 v2 firmware
Weakness type
Related vulnerabilities
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects...
- CVE-2026-20705 — Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform...
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite...
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- CVE-2026-26152 — Microsoft Cryptographic Services Elevation of Privilege Vulnerability