Command Injection Vulnerability in Zyxel ATP and USG FLEX Series Firmware
CVE-2023-34141

8HIGH

Key Information:

Summary

A command injection vulnerability exists in the access point management functionality of Zyxel's firmware, affecting several product lines. An attacker on the local network can exploit this flaw to execute arbitrary OS commands on targeted devices by manipulating the managed AP list, contingent upon convincing an authorized administrator to add their IP address. This highlights the importance of stringent access controls and vigilance in network management practices to safeguard against potential exploits.

Affected Version(s)

ATP series firmware 5.00 through 5.36 Patch 2

NXC2500 firmware 6.10(AAIG.0) through 6.10(AAIG.3)

NXC5500 firmware 6.10(AAOS.0) through 6.10(AAOS.4)

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.