Command Injection Flaw in Zyxel ATP & USG FLEX Firmware
CVE-2023-34138
8HIGH
Key Information:
- Vendor
- Zyxel
- Status
- Vendor
- CVE Published:
- 17 July 2023
Summary
A command injection vulnerability exists in the hotspot management feature of Zyxel ATP and USG FLEX series firmware versions 4.60 to 5.36 Patch 2. This flaw allows unauthenticated, LAN-based attackers to execute arbitrary operating system commands on compromised devices. The attack is initiated if the attacker successfully persuades an authorized administrator to add their IP address to the trusted RADIUS clients list. Mitigation steps are essential to prevent exploitation of this security weakness.
Affected Version(s)
ATP series firmware 4.60 through 5.36 Patch 2
USG FLEX 50(W) series firmware 4.60 through 5.36 Patch 2
USG FLEX series firmware 4.60 through 5.36 Patch 2
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved