Information Exposure Vulnerability in Zyxel ATP and USG FLEX Series Firmware
CVE-2023-22918
6.5MEDIUM
Key Information:
- Vendor
Zyxel
- Vendor
- CVE Published:
- 24 April 2023
What is CVE-2023-22918?
An information exposure vulnerability exists in the CGI program of Zyxel's ATP and USG FLEX series firmware, affecting several versions. This flaw enables remote authenticated attackers to potentially access sensitive, encrypted administrative information from affected devices. The vulnerability affects multiple products including several versions of the Zyxel ATP, USG FLEX, and VPN series firmware, as well as selected access points, putting administrative data at risk.
Affected Version(s)
ATP series firmware 4.32 through 5.35
NWA110AX firmware <= 6.50(ABTG.2)
USG FLEX 50(W) firmware 4.16 through 5.35