The new firmware logs all Telnet authentication attempts in /var/log/auth.log. Regularly review for brute-force patterns.
Regulations like IEC 62443 (Industrial Communication Networks) and NIST SP 800-82 now require that all industrial IoT devices ship with unique per-device credentials or force a password change on first login. The static zmm220 password violated multiple guidelines.
Connect via Web UI (port 80) or old Telnet credentials and run:
cat /etc/version
If the output is lower than 2.3.1, proceed with the update.
Updating the default password is just the first step. To truly secure your ZMM220 deployment, follow these recommended practices:
Earlier iterations of the ZMM220 firmware shipped with a default Telnet password. In many network environments, default credentials remain unchanged by end-users, creating a vulnerability that could be exploited by malicious actors for unauthorized remote access.
Previous Behavior:
Support For assistance with updating credentials or migrating from Telnet to SSH, contact [support email/portal].