Improper Input Validation in Zyxel ATP and USG FLEX Series Firmware
CVE-2023-35136
5.5MEDIUM
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 28 November 2023
What is CVE-2023-35136?
The Zyxel ATP and USG FLEX series firmware contain an improper input validation vulnerability within the Quagga package. This flaw permits an authenticated local attacker to potentially access sensitive configuration files on the device, which could lead to further unauthorized actions and compromise the device's integrity.
Affected Version(s)
ATP series firmware versions 4.32 through 5.37
USG FLEX 50(W) series firmware versions 4.16 through 5.37
USG FLEX series firmware versions 4.50 through 5.37