An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
ZLAN Information Technology Co. did not respond to CISA's attempts at
coordination. Users of ZLAN5143D devices are encouraged to contact ZLAN
and keep their systems up to date.
https://www.zlmcu.com/en/contatct_us.htm
https://www.zlmcu.com/en/contatct_us.htm