Command Injection Flaw in Zyxel ATP & USG FLEX Firmware
CVE-2023-34138
8HIGH
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 17 July 2023
What is CVE-2023-34138?
A command injection vulnerability exists in the hotspot management feature of Zyxel ATP and USG FLEX series firmware versions 4.60 to 5.36 Patch 2. This flaw allows unauthenticated, LAN-based attackers to execute arbitrary operating system commands on compromised devices. The attack is initiated if the attacker successfully persuades an authorized administrator to add their IP address to the trusted RADIUS clients list. Mitigation steps are essential to prevent exploitation of this security weakness.
Affected Version(s)
ATP series firmware 4.60 through 5.36 Patch 2
USG FLEX 50(W) series firmware 4.60 through 5.36 Patch 2
USG FLEX series firmware 4.60 through 5.36 Patch 2