A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product contains hard-coded credentials, such as a password or cryptographic key.