Sensitive Information Exposure in Zyxel DX5401-B0 Firmware
CVE-2023-28770
7.5HIGH
Summary
A sensitive information exposure vulnerability exists in the Zyxel DX5401-B0 firmware, specifically affecting the CGI component "Export_Log" and the binary "zcmd". This flaw enables a remote unauthenticated attacker to gain unauthorized access to system files, potentially allowing them to retrieve sensitive data including the supervisor password stored in an encrypted format. This breach underscores the importance of timely firmware updates and the need for robust security measures to protect against unauthorized access.
Affected Version(s)
DX5401-B0 firmware < V5.17(ABYO.1)C0
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved