Unauthenticated API Vulnerability in Zyxel CloudCNM SecuManager
CVE-2020-15343
5.3MEDIUM
What is CVE-2020-15343?
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 are susceptible to an unauthenticated API vulnerability that allows arbitrary execution of commands via the zy_install_user_key API endpoint. This vulnerability can enable attackers to gain unauthorized access to the system, potentially leading to further exploits and unauthorized data manipulation. Immediate remediation is advised to protect against potential threats.