Sensitive Information Exposure in Zyxel DX5401-B0 Firmware
CVE-2023-28770

7.5HIGH

Key Information:

Vendor
Zyxel
Vendor
CVE Published:
27 April 2023

Summary

A sensitive information exposure vulnerability exists in the Zyxel DX5401-B0 firmware, specifically affecting the CGI component "Export_Log" and the binary "zcmd". This flaw enables a remote unauthenticated attacker to gain unauthorized access to system files, potentially allowing them to retrieve sensitive data including the supervisor password stored in an encrypted format. This breach underscores the importance of timely firmware updates and the need for robust security measures to protect against unauthorized access.

Affected Version(s)

DX5401-B0 firmware < V5.17(ABYO.1)C0

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.