CVE-2016-10401

HIGH EXPLOITED IN THE WILD RANSOMWARE

ZyXEL PK5001Z - Default Root Password Exposure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-10401 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including Matthew Sheimo.

AI-analyzed exploit summary This exploit leverages hardcoded credentials for the ZyXEL PK5001Z modem, allowing authentication bypass via Telnet with 'admin:CenturyL1nk' and privilege escalation to root using 'su' with password 'zyad5001'. The PoC demonstrates a trivial authentication bypass and local privilege escalation.

Description

ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

Exploits (1)

exploitdb WORKING POC
by Matthew Sheimo · textremotehardware
https://www.exploit-db.com/exploits/43105

This exploit leverages hardcoded credentials for the ZyXEL PK5001Z modem, allowing authentication bypass via Telnet with 'admin:CenturyL1nk' and privilege escalation to root using 'su' with password 'zyad5001'. The PoC demonstrates a trivial authentication bypass and local privilege escalation.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ZyXEL PK5001Z Modem 2.6.20.19
No auth needed
Prerequisites: network access to the device · Telnet service enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://forum.openwrt.org/viewtopic.php?id=62266
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43105/

Scores

CVSS v3 8.8
EPSS 0.1234
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2017-11-24
InTheWild.io 2022-05-25
Ransomware Use Confirmed
CWE
CWE-255
Status published
Products (1)
zyxel/pk5001z_firmware
Published Jul 25, 2017
Tracked Since Feb 18, 2026