In firmware release 34.0, on the 9th May 2025, Zyxel fixed the security flaw that allowed an admin/user to enable the debug flag and retrieve the root password.
If anyone knows a new method of privilege escalation on this device, I'd be grateful if you would reach out to me.

In firmware release 34.0, on the 9th May 2025, Zyxel fixed the security flaw that allowed an admin/user to enable the debug flag and retrieve the root password.
If anyone knows a new method of privilege escalation on this device, I'd be grateful if you would reach out to me.