Command Injection Flaw in Zyxel ATP & USG FLEX Firmware
CVE-2023-34138

8HIGH

Key Information:

Summary

A command injection vulnerability exists in the hotspot management feature of Zyxel ATP and USG FLEX series firmware versions 4.60 to 5.36 Patch 2. This flaw allows unauthenticated, LAN-based attackers to execute arbitrary operating system commands on compromised devices. The attack is initiated if the attacker successfully persuades an authorized administrator to add their IP address to the trusted RADIUS clients list. Mitigation steps are essential to prevent exploitation of this security weakness.

Affected Version(s)

ATP series firmware 4.60 through 5.36 Patch 2

USG FLEX 50(W) series firmware 4.60 through 5.36 Patch 2

USG FLEX series firmware 4.60 through 5.36 Patch 2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.